SecondFi Suspends Operations After $2.6M ADA Theft by Lazarus Group Suspects
SecondFi halts wallet services after 374 accounts were drained of $2.6M in ADA. Lazarus Group is suspected. A ZK-based recovery tool is planned for August release.
Woofun AI reports that SecondFi has suspended its SecondFi and Yoroi wallet services following a security breach affecting 374 wallets between June 21 and 23, resulting in the theft of approximately 16.1 million ADA ($2.6 million). Investigations identified two independent attacker groups; the primary suspect is the North Korean Lazarus Group, while a second group targeted distinct wallets with no overlap. The incident stemmed from a cryptographic signature vulnerability present in both official and unauthorized GitHub code copies. SecondFi has patched the flaw and is developing a zero-knowledge proof-based recovery tool and wallet export feature, the former expected in August and the latter in early August, while warning users against unsolicited contact requesting private keys.
Comments
No comments yet.