TechFlow reports, July 22, according to CoinDesk, Cardano wallet SecondFi was attacked due to a transaction signing software vulnerability, with 374 wallets totaling 16.1 million ADA (approximately $2.4 million) stolen, and the platform announced permanent closure. The vulnerability allowed attackers to derive private keys from on-chain visible transaction data; the Cardano network itself was unaffected, and hardware wallet users were also not impacted.
Investigation by blockchain intelligence company Groom Lake, hired by EMURGO, shows that the main attackers were sophisticated and well-funded, with some indications pointing to North Korea's Lazarus Group, though not yet officially confirmed. SecondFi plans to release a wallet export tool in early August and launch a zero-knowledge recovery portal later that month; EMURGO has set up an asset recovery wallet, with the specific distribution time to be determined.



