SecondFi breach probe flags possible Lazarus-linked actor; zero-knowledge recovery tool slated for Aug. 2026

AI Market Summary
SecondFi disclosed a cryptographic flaw in wallet signature generation that could theoretically expose private key material from onchain data, linked in part to indicators associated with Lazarus Group activity. Roughly 16M ADA reportedly moved from 374 addresses, while 129M ADA was transferred to an independent custodian. Wallet shutdowns and a delayed (Aug 2026) ZK-based recovery tool raise near-term operational and trust risk for ADA-linked users.
Impact level
● High
Affected assets
ADA/USDT-0.86%
AI Insight · ADA/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ChainThink said SecondFi disclosed on July 22 that EMURGO commissioned an investigation into the project's recent security incident, carried out by independent blockchain forensics firm Groom Lake. According to the findings, the incident involved two distinct attackers. SecondFi said the primary actor matches certain indicators associated with the North Korean Lazarus Group, and additional analysis remains underway. The second actor used different wallet addresses, with evidence assessed as separate from the primary attack. SecondFi attributed the breach to a cryptographic weakness in its wallet software during transaction-signature generation. In theory, the flaw could allow an attacker to derive affected wallets' private-key material from on-chain data. SecondFi added that the vulnerable code had previously been released without authorization to a public GitHub repository. The company said it continues to evaluate developments and is cooperating with regulators. The vulnerability has been patched, and wallets created with the updated version are not impacted. SecondFi said it will wind down the SecondFi and Yoroi wallets and is building a zero-knowledge proof-based asset recovery tool, targeted for release in August 2026. Before that, it plans to roll out a wallet-export function to help users migrate assets to other wallets. SecondFi previously reported four transfers in total, three of which were executed by external attackers, moving about 16 million ADA from 374 addresses. Separately, SecondFi said it has transferred roughly 129 million ADA to an independent third-party custodian.