SecondFi, a Cardano-based wallet service, has announced it will permanently shut down following a security breach that resulted in the theft of approximately 16.1 million ADA — worth roughly $2.6 million at the time. The hack exploited an encryption flaw in the platform’s wallet software, compromising 374 user wallets and triggering widespread frustration among affected users.
The incident targeted SecondFi’s wallet infrastructure, which was closely integrated with the Yoroi wallet service. An investigation is now exploring possible links to the Lazarus Group, the North Korean state-backed hacking collective known for attacking cryptocurrency platforms. As a result, both SecondFi and Yoroi wallet services are being phased out entirely.
Initially, SecondFi pledged to support asset recovery within two weeks. However, the company has since postponed the launch of a zero-knowledge proof-based recovery tool and an asset transfer function, now expected in August. The delay has sparked backlash on social media and community forums, with users questioning the platform’s transparency and commitment to restitution.
The breach highlights persistent security vulnerabilities in DeFi wallet infrastructure, posing reputational risks for the Cardano ecosystem, which has long emphasized its research-driven security. The potential involvement of Lazarus further raises concerns about state-sponsored threats targeting smaller platforms.