Markets Closed
Global Markets
S&P 500 7,498.96 ▼ -0.1% DOW 52,218.58 ▼ -0.0% NASDAQ 25,690.9 ▼ -0.6% RUSSELL 2K 2,958.76 ▼ -1.0% VIX 16.88 ▼ -1.0% GOLD 4,136.9 ▲ +1.6% CRUDE OIL 86.48 ▲ +1.8% EUR/USD 1.14 ▲ +0.1% BTC 65,790 ▼ -0.9% ETH 1,925.2 ▲ +0.2%
Fintech

SecondFi to close wallet after $2.4 million ADA theft

SecondFi says a signature-generation flaw let attackers drain 16.1 million ADA, prompting a shutdown of SecondFi and the Yoroi wallet.

Rafael Ortiz

By Rafael Ortiz · Fintech Correspondent

· 3 min read

SecondFi to close wallet after $2.4 million ADA theft
Photo: PYMNTS

Cryptocurrency wallet provider SecondFi said it will wind down its operations after attackers stole $2.4 million from users by draining 16.1 million ADA last month. In a Wednesday update, the company said it had fixed the vulnerability and protected a further 129 million ADA before the attackers could reach those funds.

The company said the incident was severe enough to proceed with the planned closure of both SecondFi and the Yoroi wallet. It did not announce a reimbursement plan in the update, but said tools to help users move or recover wallet access are being prepared.

Signature flaw exposed key material

SecondFi attributed the theft to a technical weakness in the way its wallet software created signatures for individual transactions. In a cryptocurrency wallet, a transaction signature is used to prove that the holder of a private key has authorized a transfer without revealing the key itself.

According to SecondFi, the affected software used a value that should have depended on secret information. Under certain circumstances, the company said, that value could instead be calculated from transaction information already visible on the public blockchain.

That failure meant attackers could derive affected private key material from public data, SecondFi said. Once a private key or enough related material is exposed, an attacker may be able to authorize transfers from the wallet as if they were the legitimate holder.

SecondFi said it expects wallet export tools to be available early next month. A zero-knowledge recovery portal is planned for later in August, according to the company. Zero-knowledge systems are designed to let one party verify information or complete a recovery process without exposing the underlying secret data.

Investigators point to a well-funded attacker

SecondFi said intelligence firm Groom Lake, which was commissioned by blockchain company EMURGO, assessed that the primary attacker was external and well financed. The company said Groom Lake found indicators consistent with a professional threat actor aligned with a state.

SecondFi also said there were some signs suggesting possible involvement by North Korea’s Lazarus Group. The company did not state that the attribution had been conclusively established.

The closure adds to a year of security failures across digital asset platforms. PYMNTS reported that the SecondFi theft was far smaller than the April exploit of Kelp DAO, a decentralized finance platform, where about $292 million was stolen. That breach was followed by effects across DeFi lending markets, including nearly $9 billion erased from the largest DeFi lending platform, according to PYMNTS.

PYMNTS has described those incidents as exposing the strain between crypto systems built for openness and interoperability, and the controls required by institutions that handle regulated or large-scale financial activity.

Ryan Rugg, global head of digital assets at Citi Treasury and Trade Solutions, told PYMNTS’ “From the Block” podcast that the Kelp DAO incident could reduce confidence in the market and might slow institutional adoption of DeFi. She also said institutions would likely focus on whether companies can put redundancy and security in place at every layer where trust is required.

This story draws on original reporting from PYMNTS.

More from Fintech

All Fintech →