SecondFi Sets Recovery Timeline After $2.4M Cardano Wallet Breach
- SecondFi is implementing a three-stage recovery process after a $2.4 million breach affecting 374 Cardano wallets.
- Users must utilize the upcoming wallet migration tool to transfer their assets to a new wallet.
- Avoid deleting the original wallet or app during recovery, as they may be needed for the process.
SecondFi has outlined a three-stage recovery process following the security breach that drained approximately 16.1 million ADA, worth about $2.4 million at the time, from hundreds of Cardano wallets.
In a July 27 update, the company said it had simplified its claims process. A streamlined ticket submission feature will become available through the latest version of the SecondFi application.
The next step will involve a wallet migration tool, which SecondFi expects to release during the second week of August. All users will need to use the tool, including those whose wallets were not affected by the breach.
It will transfer a wallet’s entire Cardano balance—including ADA, native tokens, and NFTs—to a newly created wallet from another provider. The tool will also automatically unstake delegated ADA before moving it.
SecondFi warned users not to delete their original wallet or remove the application, as both could be needed during the recovery process. The migration software is provisionally complete and undergoing an independent cybersecurity audit.
A separate recovery portal is expected in early September. SecondFi said the tool, developed with support from Input Output Group, the Cardano Foundation, and other ecosystem participants, will use zero-knowledge proofs. Users should be able to prove ownership of an affected wallet without disclosing their seed phrase or private keys.
The recovery system still requires an estimated three-week security audit and another two weeks of testing and questions before release.
The breach occurred in June after attackers exploited a cryptographic flaw in SecondFi’s Cardano transaction-signing software. According to the company’s incident report, the flaw could allow private key material to be derived from transaction information visible on the blockchain.
Around 374 wallets were reportedly affected across multiple attacks. SecondFi said it also secured roughly 129 million ADA before attackers could reach the funds. The Cardano blockchain itself was not compromised, and hardware wallet users were not affected.
SecondFi, formerly known as Yoroi, has patched the faulty code but will wind down its wallet operations rather than restore normal service. Users should now watch for the audited migration tool and a confirmed September recovery date.
