If you’re having problems or errors, can’t Migrate your tokens…withdrawing of tokens send a message with the button below to contact instant support and you will be assisted
https://t.co/32BnbK4hPD
An update regarding the recent security incident involving SecondFi
What happened to SecondFi
Between June 21st and 23rd, SecondFi experienced a security incident that resulted in approximately 16.1 million ADA (~$2.6 million) being stolen from 374 wallets. We want to provide users with a transparent update based on the information currently available.
An independent investigation
EMURGO engaged Groom Lake, an independent forensic investigation / blockchain intelligence provider to assist with tracing and evidentiary analysis and they reviewed the incident using primary technical evidence, including code, code history, and public blockchain data.
What the investigation indicates to date:
1. Attack from an external actor: linked to high-volume addresses employing advanced tradecraft: @0xGroomLake indicates that the primary operation behind the unauthorised transfers was sophisticated, external, and well-funded, with indicators consistent with activity by a professional, state-aligned threat actor. Certain indicators are being assessed for potential overlap with known DPRK-linked threat activity of Lazarus Group.
2. Two separate attackers: Groom Lake also identified activity by a second party that appears, based on current evidence, to be separate from the primary operation and to have affected a different set of wallets during the same window. No overlap in affected wallets has been identified to date.
The root cause: A cryptographic flaw
The root cause was a highly subtle flaw in how the wallet software generated per-transaction signatures. In simplified terms, a value that should have been derived from secret information could, under certain conditions, be computed from public transaction data. This could enable affected private key material to be derived from information visible on the public blockchain.
This cryptographic flaw was also visible in a copy of the relevant code that had been published without authorisation to a public GitHub repository. We are continuing to assess the circumstances surrounding the publication and are cooperating with the relevant authorities.
Fix and winding down of SecondFi
The flaw has been patched, and new wallets created with the corrected software are not known to be affected by this issue. However, given the gravity of this event and as previously announced, we have made the difficult decision to wind down SecondFi and Yoroi wallet.
Asset recovery and safe migration
Our current priority is supporting affected users, assisting recovery efforts, and enabling users to move assets securely.
1. Recovery tool: A secure recovery tool using zero-knowledge (ZK) proofs is being developed. The portal is designed to allow users to initiate the process directly while limiting the information required to do so. The tool is currently in testing, and we are engaging a specialist third-party auditor to review it before its anticipated release in August 2026.
2. Safe migration: In the meantime, we are preparing wallet export functionality designed to allow users to migrate their assets to a wallet of their choice. We anticipate releasing this by early August 2026.
Please follow our official channels for further updates.
Important Security Reminder
SecondFi will NEVER request private keys, recovery phrases, or wallet credentials, and we will never DM you first. Do not trust any checker, link, or account outside our official channels:
▪️ X accounts: @secondfiapp and @secondfi_jp
▪️ Support portal: https://t.co/bKfl8SK9D2
Your Options for Securing Assets, and What’s Next
We recognize that some users may not have completed all steps in the Hardware Wallet Guidance posted in our knowledge base. If you are not technically proficient, we recommend waiting for the secure wallet export functionality, which is currently intended to launch next week.
Here is an update on upcoming options:
• This week: Quarantine mode
We will enable quarantine mode, which will let users check whether a wallet address appears in preliminary incident-related data and submit a support ticket with the relevant wallet address.
• Next week: Secure wallet export functionality
We intend to deploy secure wallet export as the next phase of quarantine mode. This is intended to provide a safer way for users of varying experience levels to move assets to a new wallet.
• On potential asset recovery
As stated previously, we intend to support a process relating to potential asset recovery for users whose wallets are confirmed through the applicable process. Any such process remains subject to further investigation, verification, eligibility criteria, applicable terms and conditions, and technical implementation.
It is currently expected to involve a recovery tool using zero-knowledge proofs, initiated by users through a portal, designed to help users remain in control of the process while protecting their information.
Again, if you are not technically proficient, we recommend waiting for these options to go live. For now, you may submit a ticket at https://t.co/bKfl8SK9D2.
We will continue sharing updates as progress is made.
Hardware Wallet Migration Guide
We have published a step-by-step guide to help users securely move their assets to a new hardware wallet, the most secure option for self-custody.
Before you start, keep these in mind:
- If you already use a hardware wallet, no action is required. Hardware wallet users were not affected by this incident.
- Do not delete the SecondFi app, and keep your seed phrase safe. Either one will be required to claim your assets through the recovery process.
- Stop using your existing wallet. Do not send, receive, sign, or stake from it.
The full step-by-step guide, including how to test with a small amount before moving your balance, is available here: https://t.co/B3RrzI83hx
Important Security Reminder
SecondFi will NEVER request private keys, seed phrases, wallet credentials, or request asset transfers under any circumstances. We will never DM you first.
Any message instructing you to move assets or submit wallet information outside of our verified official channels should be treated as fraudulent. Our official channels are @secondfiapp, @secondfi_jp, and https://t.co/bKfl8SK9D2.
For support, please submit a ticket only through our official support channel at: https://t.co/bKfl8SK9D2
🛡 Recovery Process Update
Today, we want to share an update across three areas:
⚙️ Returning user assets
⚙️ Moving user assets safely
⚙️ Onchain recovery
1. Returning User Assets
- Drained by the attackers: @emurgo_io has funded an Asset Recovery Wallet specifically to return assets to users whose wallets were compromised in the attack.
- Secured through our emergency rescue response: These assets are currently protected and accessible. We are in discussion with @IntersectMBO on the appropriate custody mechanism to ensure they are held securely and returned to users.
2. Moving Your Assets
Our initial guidance was to stay put which was a deliberate step while we worked to fully understand the attack vector and avoid exposing users to further risk. Following active discussions with the Intersect Security Council, should you decide to move your assets, we recommend creating a new wallet using a hardware wallet only. A hardware wallet is the most secure option available.
Important: However, users should NOT delete the SecondFi app under any circumstances. We strongly advise users to retain BOTH the app and their seed phrase, as they will be required to support the asset recovery process currently underway.
3. Onchain Recovery
Our team is actively progressing an on-chain recovery solution designed to support the secure return of user assets. Extensive technical assessment has identified this as the most secure and efficient recovery pathway currently available.
We are now working closely with a Cardano community-led task force to develop, validate and execute this solution securely.
This process is more complex than originally anticipated and may require additional time beyond our previously estimated 2-week timeline.
We will continue providing updates as progress continues.
Important Security Reminder:
SecondFi will NEVER request private keys, seed phrases, wallet credentials, or request asset transfers under any circumstances. We will never DM you first.
Any message instructing you to move assets or submit wallet information outside of our verified official channels should be treated as fraudulent. Our official channels are our verified SecondFi X account and https://t.co/bKfl8SK9D2.
For support, please submit a ticket only through our official support channel at: https://t.co/bKfl8SK9D2
Thank you for your continued trust as this work continues.
🛡 Recovery Process Status
The team remains on track against the estimated 2-week recovery timeline, with substantial progress continuing as engineering teams work through multiple technical approaches in parallel to determine the most secure recovery solution for affected users.
What Comes Next:
To help users safely prepare for the upcoming next steps, we will be releasing:
1. A suitable mechanism that will allow users to check whether their wallet has been affected by early next week
2. A secure process that will allow users to safely move assets out of the platform thereafter.
Our commitment remains unchanged: protecting users and ensuring assets are returned securely.
Important Security Reminder:
At this stage, NO recovery actions requiring user participation have begun.
Until official instructions are provided, wallets should remain untouched and users should continue to rely only on updates shared through official SecondFi channels.
SecondFi will NEVER request private keys, seed phrases, wallet credentials, or request asset transfers under any circumstances.
Should you have any questions, please submit a ticket only through our official support channel at: https://t.co/bKfl8SK9D2
We remain fully committed to completing this process safely and responsibly, and thank you for your continued support.
📢 Important Guidance for SecondFi Users
We understand that many users are considering migrating to new wallets, and that trusted members of the Cardano community are suggesting ways to do so. We recognise this comes from a desire to protect your assets. If you choose to migrate, you do so at your own risk.
However, we strongly advise against taking this action at this time. Particularly if you are not technical, the safest course is to leave it untouched.
Independent actions taken outside of official guidance create additional risks, and may significantly complicate the asset claims process. Our team is working through a secure recovery process, and we will continue keeping users updated as progress is made. Official step by step instructions will follow shortly.
If you have a query, you may submit a ticket at: https://t.co/bKfl8SK9D2. We will never DM you first or ask for your recovery phrase.
Thank you for your patience.
To provide more clarity, we have identified the nature of the incident, it is at the address level. The security risk affects wallet users when a transaction is signed.
Therefore recovery to another platform or wallet does not mitigate the risk.
🚨 DO NOT restore your recovery phrase into a new Cardano wallet.
We have isolated the affected wallets and will post mitigation steps shortly.
As per our previous post:
https://t.co/LGhovIoI3T
We have identified the root cause and have since rolled out a patch for all unaffected wallets. This will allow us to resume normal operations soon.
-----
Regarding affected wallets, 4 distinct draining events occurred. 3 were executed by external threat actors, resulting in a loss of ~16m ADA across 374 addresses.
To prevent total loss during the active exploit, emergency rescue measures were triggered to secure the available ~129m ADA and continues to be routed to an independent, qualified third-party custodian, where they are held securely for the benefit of the affected wallet addresses.
An external accounting firm has been engaged for a special audit to independently verify those holdings.
We are working to facilitate the verification process so users can claim back their assets safely. Affected users should submit their claim at https://t.co/bKfl8SK9D2
We take this incident seriously and are working to ensure all assets are returned to affected users as soon as possible.
As stated, we have identified the root cause, it is at the address level. Please DO NOT RESTORE your recovery phrase into another Cardano wallet, this does not mitigate the security risk. The security risk occurs when an affected user signs a transaction.
Further explanation to follow.
Important Security Update.
As stated, we have identified the root cause of the incident. It is at the address level.
The affected software signer used a deterministic nonce derivation flaw. Every time an address signed a transaction, it leaked enough information to mathematically reconstruct that address's private key from public blockchain data alone.
If you were affected by the attack, your first/default address (index 0) is almost certainly exposed. It is the address that some wallets may be using by default or as the only address at all, and nearly always has transactions. That history is all an attacker needs.
Please DO NOT RESTORE your recovery phrase into another Cardano wallet. This does not mitigate the security risk.
Your keys are derived from your recovery phrase, not from the app. Restoring the same phrase into another wallet recreates identical addresses with identical exposure. The compromised thing is the key of the compromised address(es), not the interface you are using.
If you were affected by the attack, and use any of your compromised address(es) to deposit it could be drained again. This includes withdrawing staking rewards even using another wallet.
Reward withdrawal and delegation are signed with the stake credential. The withdrawn funds could be routed to your first/default address (as indicated above), which has a high chance of being compromised (wallets work differently managing it). Mempool-monitoring adversaries can front-run or sweep your assets on confirmation.
There has been conflicting advice from community members in an attempt to be helpful. Do nothing until official steps come from SecondFi.
We are working to facilitate the verification process so users can claim back their assets safely. Following the above is very important, if not it makes verified claims more difficult.
The only thing you should do right now is submit a ticket at https://t.co/bKfl8SK9D2
We will never DM you first or ask for your recovery phrase.