Back to News
ImportantSourceMarsBit

SecondFi 因 260 万美元 ADA 被盗将逐步关闭钱包服务

火星财经消息,Cardano 生态钱包 SecondFi 表示,因钱包软件加密缺陷导致约 1,610 万枚 ADA 被盗,价值约 260 万美元,平台将逐步关闭 SecondFi 和 Yoroi 钱包服务。此次事件影响 374 个钱包。SecondFi 表示,区块链情报机构 Groom Lake 的独立调查认定攻击方为复杂外部行为者,并发现可能与朝鲜 Lazarus Group 相关的指标,但尚未确认归因。SecondFi 正在开发基于零知识证明的恢复工具,以帮助受影响用户恢复资产并限制需共享的信息。该工具仍在测试中,并将在计划于 8 月发布前接受第三方审计。SecondFi 还在准备钱包导出功能,允许用户将资产迁移至其他服务。平台未公布直接赔偿计划,也未说明是否将使用自有资金补偿用户。
Disclaimer: The views above are the author's only and do not represent 711BTC. Nothing here constitutes investment advice.

Related

07-07 10:54Important

EMURGO announced that SecondFi, the Cardano wallet that was hacked, will permanently cease operations.

ChainCatcher reports that Cardano's founding entity, EMURGO, stated on Monday that SecondFi, the wallet service that suffered a hack, will not resume normal operations even after a security audit is completed. All users are required to migrate their assets through the official recovery process. SecondFi is a rebranded version of the Yoroi wallet and is described by EMURGO as Cardano's largest wallet provider. According to EMURGO's incident report on June 25th, the service suffered four separate wallet thefts on June 22nd, with 374 addresses compromised and approximately 16 million ADA (worth about $2.4 million at the time) stolen. The team also took emergency measures to recover approximately 129 million ADA. EMURGO stated that compromised wallets should be considered permanently exposed at the address and private key levels, and restoring the damaged seed phrase to other wallets cannot eliminate the risk. EMURGO plans to launch an isolated wallet state inspection tool this week, followed by a secure export tool and an offline migration workshop in Tokyo. They are also building a dedicated recovery fund for the on-chain recovery system, and will return assets to affected users after the external audit is completed.

06-24 17:54Important

SecondFi: 374 addresses lost approximately 16 million ADA; affected users can submit compensation claims.

PANews reported on June 24 that SecondFi, the Cardano wallet service provider, stated that it has identified the root cause of the recent security incident and deployed patches for unaffected wallets, and is about to resume normal operations. SecondFi disclosed that there were four instances of funds being transferred out during the incident, three of which were carried out by external attackers, resulting in approximately 16 million ADA being transferred from 374 addresses. To mitigate further losses during the ongoing attack, SecondFi initiated an emergency transfer, moving approximately 129 million ADA to an independent third-party escrow institution for safekeeping, and has engaged an external accounting firm to conduct a special audit to facilitate subsequent verification and return of assets to affected addresses.

06-24 08:16

SecondFi: Security incident affects approximately 16 million ADA; issue stems from web wallet generation software.

PANews reported on June 24th that SecondFi, a Cardano ecosystem project, released a security incident update, stating that the root cause has been identified and the issue is limited to its native Cardano web wallet generation software. The initial estimate of the total impact is approximately 16 million ADA (currently worth about $2.42 million). The team has completed on-chain analysis and is conducting an independent technical review with a blockchain security company to verify the results. The platform remains in security maintenance mode, and a full snapshot of the balance has been taken. For affected users, the team has taken extraordinary measures to protect their remaining assets and will strive to compensate them.

06-23 14:48

SecondFi: A small number of Cardano wallets have been found to be affected by security issues, and the platform has entered maintenance mode.

According to Foresight News , SecondFi, a custodial financial platform, tweeted that it had discovered a security issue affecting a small number of Cardano wallets. The issue has been brought under control, and affected functionality has been temporarily suspended. To protect users, SecondFi has temporarily entered maintenance mode, suspending all front-end interactions, and users are temporarily unable to trade. The team is working diligently to restore platform functionality.

06-30 12:54Important

SecondFi: On-chain recovery solution is more complex than expected; recovery time may exceed two weeks.

Odaily Odaily reports that Cardano wallet service provider SecondFi has released an update on the security incident recovery, stating that EMURGO has established an asset recovery fund to return assets to users affected by the attack. SecondFi stated that it has taken emergency measures to protect and restore access to some assets, and the team is discussing a suitable custody mechanism with Intersect to ensure the safe return of the relevant assets to users. In addition, SecondFi is collaborating with a Cardano community-led working group to advance the on-chain recovery plan. Due to the greater complexity of the recovery plan than previously anticipated, the overall recovery time may exceed the initial estimate of two weeks.

06-29 19:50Important

SecondFi released an update on the progress of user asset recovery: the entire process may take longer than the previously estimated two weeks.

PANews reported on June 29th that SecondFi released an update on its recovery progress, focusing on the return of user assets, secure asset migration, and on-chain recovery solutions. Regarding the assets stolen by the attackers, Emurgo has injected funds into a dedicated asset recovery wallet to return funds to affected users. Assets protected through SecondFi's emergency response are currently safe and available, and the team is negotiating custody and return mechanisms with IntersectMBO. SecondFi stated that it will work with the Cardano community working group to advance the on-chain recovery solution, but the entire process may exceed the previously estimated two-week period. The official statement reiterated that they will not solicit private keys, seed phrase, or send private messages to users in any form; users should only submit support tickets through the official website's support channels.