Hello @nativ_truth, the migration tool will appear on your wallet app automatically, you don’t have to download the migration tool. If it doesn’t appear, send us a dm so we look into it and get things resolved.
@bmoneybgreat@Stockslugger49@secondfiapp@secondfi_help Hello. Ive only used yoroi on my laptop. I created a new Lace wallet. So do I have to download the mig tool to my laptop or to my phone? Can I download it to my laptop?
⚠️ Recovery Update: Bounty Offer Made to Attacker
To keep our community informed on our recovery efforts, we want to provide more context regarding the second attack that occurred during the recent security incident.
Context on the 2nd Attack: Shortly after the initial breach, a second, entirely unrelated party exploited the same vulnerability. This independent actor capitalized on the exploit to drain an additional ~4 million ADA (along with various Cardano Native Tokens) from compromised user wallets.
Our Outreach & Bounty Offer: Approximately two weeks ago, we contacted this secondary attacker directly via an onchain message sent to the wallet holding the stolen funds. We offered a standard white-hat resolution:
🔹 Return 90% of the funds (3,618,421 ADA + CNTs) to our recovery address
🔹 Retain 10% (402,047 ADA) as a bounty
🔹 Deadline: 10 July 2026, 23:59 UTC
The onchain message can be verified here: https://t.co/jXyhX8FzhW
The deadline has passed and we have yet to receive a response.
As stated in our message, this offer does not waive any rights, remedies, claims, or options, including the ability to continue the investigation, coordinate with third parties, or pursue legal and law enforcement channels where appropriate.
We will share further updates through our official channels.
An update regarding the recent security incident involving SecondFi
What happened to SecondFi
Between June 21st and 23rd, SecondFi experienced a security incident that resulted in approximately 16.1 million ADA (~$2.6 million) being stolen from 374 wallets. We want to provide users with a transparent update based on the information currently available.
An independent investigation
EMURGO engaged Groom Lake, an independent forensic investigation / blockchain intelligence provider to assist with tracing and evidentiary analysis and they reviewed the incident using primary technical evidence, including code, code history, and public blockchain data.
What the investigation indicates to date:
1. Attack from an external actor: linked to high-volume addresses employing advanced tradecraft: @0xGroomLake indicates that the primary operation behind the unauthorised transfers was sophisticated, external, and well-funded, with indicators consistent with activity by a professional, state-aligned threat actor. Certain indicators are being assessed for potential overlap with known DPRK-linked threat activity of Lazarus Group.
2. Two separate attackers: Groom Lake also identified activity by a second party that appears, based on current evidence, to be separate from the primary operation and to have affected a different set of wallets during the same window. No overlap in affected wallets has been identified to date.
The root cause: A cryptographic flaw
The root cause was a highly subtle flaw in how the wallet software generated per-transaction signatures. In simplified terms, a value that should have been derived from secret information could, under certain conditions, be computed from public transaction data. This could enable affected private key material to be derived from information visible on the public blockchain.
This cryptographic flaw was also visible in a copy of the relevant code that had been published without authorisation to a public GitHub repository. We are continuing to assess the circumstances surrounding the publication and are cooperating with the relevant authorities.
Fix and winding down of SecondFi
The flaw has been patched, and new wallets created with the corrected software are not known to be affected by this issue. However, given the gravity of this event and as previously announced, we have made the difficult decision to wind down SecondFi and Yoroi wallet.
Asset recovery and safe migration
Our current priority is supporting affected users, assisting recovery efforts, and enabling users to move assets securely.
1. Recovery tool: A secure recovery tool using zero-knowledge (ZK) proofs is being developed. The portal is designed to allow users to initiate the process directly while limiting the information required to do so. The tool is currently in testing, and we are engaging a specialist third-party auditor to review it before its anticipated release in August 2026.
2. Safe migration: In the meantime, we are preparing wallet export functionality designed to allow users to migrate their assets to a wallet of their choice. We anticipate releasing this by early August 2026.
Please follow our official channels for further updates.
Important Security Reminder
SecondFi will NEVER request private keys, recovery phrases, or wallet credentials, and we will never DM you first. Do not trust any checker, link, or account outside our official channels:
▪️ X accounts: @secondfiapp and @secondfi_jp
▪️ Support portal: https://t.co/bKfl8SK9D2
⚠️ Security Alert: FAKE RECOVERY EMAIL
A phishing email claiming to be from SecondFi is being sent to users. Please see the example below.
The email tells you to enter “Quarantine Mode” and sign a Service Agreement to recover your assets, and warns that you will lose them if you do not. This is false. There is no such agreement, and there is no recovery step that requires you to sign anything.
The only action we ask of you right now is submitting a support ticket. If any message asks you to do more than check your wallet and submit a ticket, it is a scam.
SecondFi will never request your recovery phrase, private keys, or wallet credentials, and we will never DM or email you first. Do not click the link in that email, and do not sign or approve anything it leads to.
Only trust our official channels:
▪️X accounts: @secondfiapp and @secondfi_jp
▪️Support portal: https://t.co/bKfl8SK9D2
▪️Wallet status: check in the SecondFi app, or use https://t.co/EGLOj6iKDl if you cannot access the app
Quarantine Mode Is now live across Chrome extension, iOS, and Android.
What you need to do:
- If your SecondFi app is still in maintenance mode and not quarantine mode, you are on an older version. Please update your existing app to the latest version through your app store if it has not updated automatically.
IMPORTANT: This is the same app. Do not download a new or separate app.
What quarantine mode means:
- It's the same application, with transactions disabled
- You can view your balance and wallet address only
- You cannot send, swap, or move funds
Please protect yourself from scams.
Only download SecondFi from our official link: https://t.co/vmEn757KfC
Do not accept download links from anyone else, including emails, messages claiming to be from SecondFi.
⚠️ SecondFi Is Currently in Quarantine Mode
SecondFi is running in quarantine mode. It's the same application, but transactions are disabled. You can view your balance and wallet address only, you cannot send, swap, or move funds.
A screenshot is below so you know what to expect.
Please protect yourself from scams. Only download SecondFi from our official link: https://t.co/hkFtUebtxo
Do not accept download links from anyone else, including emails, messages claiming to be from SecondFi.
Chrome extension is live, app store is pending store approval.
How to check if your SecondFi / Yoroi Wallet was affected and submit a support ticket
Step 1: With quarantine mode now live, you can view your balance and check whether your wallet address was affected in the recent incident.
If your wallets are potentially impacted, a warning banner will appear on your Home screen in the SecondFi app. Tap it to view your wallet status.
Please note that statuses are based on preliminary, non-final data from our review of the incident and remain subject to further review.
Security Alert: Fake SecondFi Extensions and Apps
We've seen scammers create fake SecondFi browser extensions and apps. Please read this before you install anything or click any link claiming to be from us. There is no new application or link, it is the same.
Do not accept links from anyone, including people claiming to be SecondFi team members, support, or partners. We will not DM or email you links to download software, sign a transaction, or take any action with your assets. If you receive a message like that, it's a scam. Do not click it.
The only official SecondFi extension is "searchable" in the Chrome Web Store. If you see any other extension using the SecondFi name or branding, it's fake.
Check for the verified blue checkmark. Our official extension listing carries a blue verified check, shown in the screenshots below. If the listing you're looking at doesn't have it, do not install it.
Scammers can and do clone extensions and apps to steal funds. When in doubt, go directly to https://t.co/C5s1yFPlq1 and verify links yourself rather than trusting anything sent to you.
Please check carefully that you are using the correct application
SecondFi / Yoroi Wallet Guidance Sessions in Tokyo and Osaka
We are hosting dedicated in-person guidance sessions during for SecondFi and Yoroi Wallet users affected by the security incident.
Each session will include:
- A SecondFi / Yoroi update from our CEO
- A live Q&A with our specialists
- Migration guidance slides
Our team will answer your questions and walk you through best practices for securing your wallet, or safely migrating it using the secure wallet export functionality, which will be released soon.
Please note the guidance slides are informative only. We will not conduct 1:1 or hands-on wallet troubleshooting.
EVENT DETAILS:
📍 Tokyo: Melody Line Hall, 1F, WebX Venue
(The Prince Park Tower Tokyo, Minato City)
📅 Tuesday, 14 July 2026, 12:00 to 18:45 JST
Register here: https://t.co/wUwmLIEZbi
📍 Osaka: TKP Garden City Umeda Osaka
📅 Saturday, 18 July 2026, 12:00 to 17:45 JST
Register here: https://t.co/tpTZ5ZuHHY
Sessions are held in English and Japanese. Registration via Luma is required for both, and support is first-come, first-served.
Your Options for Securing Assets, and What’s Next
We recognize that some users may not have completed all steps in the Hardware Wallet Guidance posted in our knowledge base. If you are not technically proficient, we recommend waiting for the secure wallet export functionality, which is currently intended to launch next week.
Here is an update on upcoming options:
• This week: Quarantine mode
We will enable quarantine mode, which will let users check whether a wallet address appears in preliminary incident-related data and submit a support ticket with the relevant wallet address.
• Next week: Secure wallet export functionality
We intend to deploy secure wallet export as the next phase of quarantine mode. This is intended to provide a safer way for users of varying experience levels to move assets to a new wallet.
• On potential asset recovery
As stated previously, we intend to support a process relating to potential asset recovery for users whose wallets are confirmed through the applicable process. Any such process remains subject to further investigation, verification, eligibility criteria, applicable terms and conditions, and technical implementation.
It is currently expected to involve a recovery tool using zero-knowledge proofs, initiated by users through a portal, designed to help users remain in control of the process while protecting their information.
Again, if you are not technically proficient, we recommend waiting for these options to go live. For now, you may submit a ticket at https://t.co/bKfl8SK9D2.
We will continue sharing updates as progress is made.
The Wake Team has distributed early supporters their initial rewards.
Holders of these rewards will be eligible for future fee distributions and 50% of our team supply.
We appreciate your support and we will be building with you!
It’s time to wake up @base.
This week we’ll be going over our new UI/UX, new release within the hub and brand new revenue flywheel for $WAKE.
We’re shipping at rapid speed like always.
Use the full Wake Terminal now on https://t.co/sjvVdMkym2
Wake is live on @virtuals_io.
This is the beginning of Wake becoming the main @base intelligence terminal, with $WAKE at the core.
We’re excited to be a part of the biggest ecosystem on @base and we thank @virtuals_io for the opportunity.
Time to wake everyone up. https://t.co/UfP7kIjDgI
The Wake Team has chosen to reward early supporters and community in a special way. You’re part of our team.
Not only an airdrop, but 50% of the token fees and 50% of our team supply is reserved for you. Fees airdropped every week so you don’t have to wait long. The more you held in the snapshot, the bigger your cut.
The airdrop is specific amount, approximately half of our pre buy. Allocations are according to held amounts in the snapshot and some specific supporters get a bonus for bringing us to where we are today.
The Wake Team is making progress over the weekend, we’ve strategized and prepared for coming week.
The terminal is being upgraded too, for an easier UX and UI via a mode switch: “terminal mode” & “easy mode”.
Wake is for everyone on @base.
Wake up.
We may be quieter on X, but behind the scenes we’re busier than ever.
This coming week brings:
• Our biggest strategic development to date.
• A complete new UI and UX toggle mode.
• New ecosystem expansion.
• Redacted.
Enjoy your Sunday! And stay ready for the coming week.
$WAKE.