UPDATE 4: SecondFi recovery moves closer, but the platform’s future takes an unexpected turn
Since our last update, the SecondFi situation has changed in a significant way. The biggest development is not another recovery estimate, it is the direction SecondFi itself is taking. SecondFi has now confirmed that the platform will not return to normal operations following the incident. Instead, the team says its remaining focus will be dedicated entirely toward completing the recovery process for affected users.
End of an era //
For many users, this marks a major turning point. When the incident first occurred, the assumption was that SecondFi would eventually recover, strengthen security, and reopen. That expectation has now changed. The recovery effort is no longer a temporary interruption, it has become the final chapter of SecondFi as users knew it.
The next phase begins //
The recovery process has now moved from preparation into execution. SecondFi has released its wallet verification system, allowing users to begin checking their status and determine whether their wallets are included in the recovery process. This is the first time users have been able to get a clearer picture of their individual situation. For weeks, many users were left waiting without knowing whether they were affected, unaffected, or caught somewhere in between. That uncertainty is now beginning to decrease.
SecondFi has also provided more details about what happened during the security incident. According to the company and an independent forensic investigation conducted by Groom Lake, two separate attackers exploited the same vulnerability during the June incident. Investigators say the primary attacker appears to be a sophisticated external threat actor using advanced techniques, with some indicators currently being assessed for possible overlap with activity previously linked to the Lazarus Group. SecondFi emphasized that this assessment remains part of an ongoing investigation.
The investigation also found that a second, unrelated attacker exploited the same vulnerability shortly after the initial breach, draining approximately 4 million ADA, along with various Cardano native tokens, from a separate group of affected wallets. According to the investigation, no overlap has been identified between the wallets affected by the two attackers.
Recovery efforts continue //
SecondFi says it has already attempted to negotiate directly with the second attacker. SecondFi sent an on-chain message offering what it described as a standard white-hat resolution. Under the proposal, the attacker could return 90% of the stolen funds while keeping the remaining 10% as a bounty.
The deadline expired on July 10 without a response. SecondFi says it will continue working with investigators, third parties, and law enforcement where appropriate as recovery efforts move forward.
The company has also released additional technical information about the vulnerability itself. According to SecondFi, the incident was caused by a subtle cryptographic flaw affecting how transaction signatures were generated. Under certain conditions, information that should have remained secret could instead be derived from publicly available blockchain data, potentially allowing attackers to reconstruct private key material from affected wallets.
SecondFi also revealed that a copy of the vulnerable code had been published without authorization to a public GitHub repository. The company says it is continuing to investigate how that occurred while cooperating with the appropriate authorities.
The community looks ahead //
With the future of SecondFi now changing, attention has started shifting toward what happens after recovery. For affected users, the immediate goal remains simple: Get their assets back. But beyond that, the larger questions will likely continue.
What lessons will Cardano wallet developers take from this incident? How will users evaluate wallet providers moving forward? And will this event change expectations around third-party wallet security? Those questions may remain long after the recovery process is complete.
The final chapter of SecondFi //
The coming weeks will likely determine the most important part of this story. Not only whether recovery succeeds, but how the community remembers SecondFi. A project that faced a major security incident. A company that attempted a recovery effort. And a platform that ultimately had to shift its entire purpose from building a wallet to helping users leave one behind. For now, SecondFi says recovery remains the priority. Users are waiting for the next steps, and the industry is watching closely. Because sometimes the aftermath of an incident reveals just as much as the incident itself.
Latest from SecondFi on X: //
On July 15, SecondFi provided its latest instructions for affected users as quarantine mode officially went live.
The new system allows users to check whether their wallet address appears in the preliminary incident data. If a wallet is potentially impacted, a warning banner will appear inside the SecondFi app, allowing users to view their current wallet status. SecondFi emphasized that these results are based on preliminary information and are not yet considered final determinations of impact, eligibility, recovery, or liability. The company has also opened the claim submission process for affected users through its support portal. Users are being asked to provide their contact information and affected wallet addresses when submitting a claim.
SecondFi continues to advise users not to use or remove affected wallets while the recovery process is ongoing, stating that those wallets may be relevant to the formal review process. The company has also repeated its warning that users should not delete the SecondFi app. According to SecondFi, users should retain both the app and their seed phrase, as at least one may be required during the recovery process.
Latest from EMURGO on X: //
On July 8, EMURGO announced that it was stepping down from its duties as a member of the Pentad, stating that its immediate priority is now focused on the SecondFi recovery effort.
The company said resources are being redirected toward helping affected users and that the decision reflects its responsibility as a founding entity of Cardano. EMURGO also provided a recovery update, stating that quarantine mode would allow users to check whether their wallets appear in preliminary incident data and submit support tickets.
The company said the next stage would involve a secure wallet export process designed to help affected users safely move assets to new wallets, while work continues on a recovery tool intended to keep users in control of their information throughout the process.
Wrap up //
SecondFi has officially moved into the recovery phase, with quarantine mode now allowing users to check their wallet status and begin submitting claims. EMURGO has shifted focus toward supporting the recovery effort, with additional tools being developed to help affected users safely recover and move their assets.
The biggest takeaway is that recovery is no longer just being planned, it is now actively underway.
We are monitoring this closely and will share updates as more information becomes available. Subscribe to stay informed.
Original: SecondFi / Yoroi Wallet Drain
UPDATE 2: SecondFi / Yoroi Wallet Drain
UPDATE 3: SecondFi / Yoroi Wallet Drain
Since our last update, the SecondFi situation has changed in a significant way. The biggest development is not another recovery estimate, it is the direction SecondFi itself is taking. SecondFi has now confirmed that the platform will not return to normal operations following the incident. Instead, the team says its remaining focus will be dedicated entirely toward completing the recovery process for affected users.
End of an era //
For many users, this marks a major turning point. When the incident first occurred, the assumption was that SecondFi would eventually recover, strengthen security, and reopen. That expectation has now changed. The recovery effort is no longer a temporary interruption, it has become the final chapter of SecondFi as users knew it.
The next phase begins //
The recovery process has now moved from preparation into execution. SecondFi has released its wallet verification system, allowing users to begin checking their status and determine whether their wallets are included in the recovery process. This is the first time users have been able to get a clearer picture of their individual situation. For weeks, many users were left waiting without knowing whether they were affected, unaffected, or caught somewhere in between. That uncertainty is now beginning to decrease.
SecondFi has also provided more details about what happened during the security incident. According to the company and an independent forensic investigation conducted by Groom Lake, two separate attackers exploited the same vulnerability during the June incident. Investigators say the primary attacker appears to be a sophisticated external threat actor using advanced techniques, with some indicators currently being assessed for possible overlap with activity previously linked to the Lazarus Group. SecondFi emphasized that this assessment remains part of an ongoing investigation.
The investigation also found that a second, unrelated attacker exploited the same vulnerability shortly after the initial breach, draining approximately 4 million ADA, along with various Cardano native tokens, from a separate group of affected wallets. According to the investigation, no overlap has been identified between the wallets affected by the two attackers.
Recovery efforts continue //
SecondFi says it has already attempted to negotiate directly with the second attacker. SecondFi sent an on-chain message offering what it described as a standard white-hat resolution. Under the proposal, the attacker could return 90% of the stolen funds while keeping the remaining 10% as a bounty.
The deadline expired on July 10 without a response. SecondFi says it will continue working with investigators, third parties, and law enforcement where appropriate as recovery efforts move forward.
The company has also released additional technical information about the vulnerability itself. According to SecondFi, the incident was caused by a subtle cryptographic flaw affecting how transaction signatures were generated. Under certain conditions, information that should have remained secret could instead be derived from publicly available blockchain data, potentially allowing attackers to reconstruct private key material from affected wallets.
SecondFi also revealed that a copy of the vulnerable code had been published without authorization to a public GitHub repository. The company says it is continuing to investigate how that occurred while cooperating with the appropriate authorities.
The community looks ahead //
With the future of SecondFi now changing, attention has started shifting toward what happens after recovery. For affected users, the immediate goal remains simple: Get their assets back. But beyond that, the larger questions will likely continue.
What lessons will Cardano wallet developers take from this incident? How will users evaluate wallet providers moving forward? And will this event change expectations around third-party wallet security? Those questions may remain long after the recovery process is complete.
The final chapter of SecondFi //
The coming weeks will likely determine the most important part of this story. Not only whether recovery succeeds, but how the community remembers SecondFi. A project that faced a major security incident. A company that attempted a recovery effort. And a platform that ultimately had to shift its entire purpose from building a wallet to helping users leave one behind. For now, SecondFi says recovery remains the priority. Users are waiting for the next steps, and the industry is watching closely. Because sometimes the aftermath of an incident reveals just as much as the incident itself.
Latest from SecondFi on X: //
On July 15, SecondFi provided its latest instructions for affected users as quarantine mode officially went live.
The new system allows users to check whether their wallet address appears in the preliminary incident data. If a wallet is potentially impacted, a warning banner will appear inside the SecondFi app, allowing users to view their current wallet status. SecondFi emphasized that these results are based on preliminary information and are not yet considered final determinations of impact, eligibility, recovery, or liability. The company has also opened the claim submission process for affected users through its support portal. Users are being asked to provide their contact information and affected wallet addresses when submitting a claim.
SecondFi continues to advise users not to use or remove affected wallets while the recovery process is ongoing, stating that those wallets may be relevant to the formal review process. The company has also repeated its warning that users should not delete the SecondFi app. According to SecondFi, users should retain both the app and their seed phrase, as at least one may be required during the recovery process.
Latest from EMURGO on X: //
On July 8, EMURGO announced that it was stepping down from its duties as a member of the Pentad, stating that its immediate priority is now focused on the SecondFi recovery effort.
The company said resources are being redirected toward helping affected users and that the decision reflects its responsibility as a founding entity of Cardano. EMURGO also provided a recovery update, stating that quarantine mode would allow users to check whether their wallets appear in preliminary incident data and submit support tickets.
The company said the next stage would involve a secure wallet export process designed to help affected users safely move assets to new wallets, while work continues on a recovery tool intended to keep users in control of their information throughout the process.
Wrap up //
SecondFi has officially moved into the recovery phase, with quarantine mode now allowing users to check their wallet status and begin submitting claims. EMURGO has shifted focus toward supporting the recovery effort, with additional tools being developed to help affected users safely recover and move their assets.
The biggest takeaway is that recovery is no longer just being planned, it is now actively underway.
We are monitoring this closely and will share updates as more information becomes available. Subscribe to stay informed.
Original: SecondFi / Yoroi Wallet Drain
UPDATE 2: SecondFi / Yoroi Wallet Drain
UPDATE 3: SecondFi / Yoroi Wallet Drain
×
SUBSCRIBE TO SESSION ///
Catch the freshest Session sent straight to your inbox as soon as it's dropped!
Catch the freshest Session sent straight to your inbox as soon as it's dropped!
