Login
Sign Up
Woofun AI reports that SecondFi identified a cryptographic flaw in wallet signature generation as the root cause of the security incident, which allowed private key derivation from on-chain data. Forensic analysis suggests the primary attacker utilized techniques overlapping with North Korea’s Lazarus Group, while a second attacker operated independently. The vulnerability has been patched, and SecondFi announced the shutdown of its SecondFi and Yoroi wallets. An asset recovery tool based on zero-knowledge proofs is expected in August 2026, preceded by a wallet export feature. Approximately 16 million ADA was moved from 374 addresses, with 129 million ADA transferred to a third-party custodian.