SecondFi says it will shut down after a security breach at its Cardano-based wallet led to the theft of about 16.1 million ADA, or roughly $2.6 million. The incident affected 374 wallets and has left users waiting for recovery options, with no reimbursement plan announced.

Shutdown follows breach

The company said the attack exposed broader concerns around wallet security and will lead to the wind-down of both SecondFi and Yoroi wallet services. The stolen funds were taken after attackers exploited what SecondFi described as a cryptographic flaw in its wallet software.

The breach has become a defining event for the project, shifting its focus from normal operations to incident response and eventual closure. While the company has not outlined compensation for losses, it has said it is working on tools intended to help affected users regain access to assets where possible or move funds elsewhere.

Probe points to sophisticated attacker

According to an independent investigation, the attack was carried out by a sophisticated external actor. The probe also found indicators that could potentially link the incident to North Korea’s Lazarus Group, though that attribution remains tentative.

The findings add to the seriousness of the breach, but the available information does not present a final public conclusion beyond the reported indicators. SecondFi has framed the exploit as the result of a flaw in its software rather than user error.

Recovery tools delayed to August

SecondFi had previously expected recovery tools and migration options to be ready within weeks of the exploit. That timeline has now slipped, with the company targeting August for release.

One of the main tools in development is a recovery system based on zero-knowledge proofs. SecondFi said the design is intended to help affected users recover assets while limiting how much information they need to disclose. The company also said the tool is expected to undergo third-party auditing before release.

Alongside that effort, SecondFi is building a wallet export feature that would allow users to migrate assets to another service. Both tools are central to the company’s remaining response as it prepares to discontinue its wallet offerings.

User frustration and unresolved losses

The delay has prompted frustration from users affected by the theft, many of whom are still awaiting a workable path forward. For now, the company has not announced any reimbursement program, leaving recovery efforts focused on technical solutions rather than direct compensation.

The case highlights the risks tied to wallet software flaws, especially when recovery depends on custom tools that may take time to build and audit. With SecondFi now planning to wind down, the immediate question for affected users is whether the promised recovery and migration tools arrive on the revised August schedule.

Source: cointelegraph.com