According to Foresight News, SecondFi's investigation, conducted by independent forensic firm Groom Lake on behalf of EMURGO, has identified two separate attackers behind the Cardano wallet service's security breach. The primary attacker used advanced techniques with indicators overlapping with known activities of North Korea's Lazarus Group, which is under further assessment. A second independent attacker was also identified.
The root cause was a cryptographic flaw in the wallet software's transaction signature generation, which theoretically allowed attackers to derive private key material from public blockchain data. SecondFi has fixed the vulnerability and announced it will develop a zero-knowledge proof-based asset recovery tool, expected to launch in August 2026. The breach resulted in approximately 16 million ADA transferred from 374 addresses, while SecondFi has moved approximately 129 million ADA to independent third-party custody.