SecondFi 因 260 万美元 ADA 被盗将逐步关闭钱包服务
Related
EMURGO announced that SecondFi, the Cardano wallet that was hacked, will permanently cease operations.
ChainCatcher reports that Cardano's founding entity, EMURGO, stated on Monday that SecondFi, the wallet service that suffered a hack, will not resume normal operations even after a security audit is completed. All users are required to migrate their assets through the official recovery process. SecondFi is a rebranded version of the Yoroi wallet and is described by EMURGO as Cardano's largest wallet provider. According to EMURGO's incident report on June 25th, the service suffered four separate wallet thefts on June 22nd, with 374 addresses compromised and approximately 16 million ADA (worth about $2.4 million at the time) stolen. The team also took emergency measures to recover approximately 129 million ADA. EMURGO stated that compromised wallets should be considered permanently exposed at the address and private key levels, and restoring the damaged seed phrase to other wallets cannot eliminate the risk. EMURGO plans to launch an isolated wallet state inspection tool this week, followed by a secure export tool and an offline migration workshop in Tokyo. They are also building a dedicated recovery fund for the on-chain recovery system, and will return assets to affected users after the external audit is completed.
SecondFi: 374 addresses lost approximately 16 million ADA; affected users can submit compensation claims.
PANews reported on June 24 that SecondFi, the Cardano wallet service provider, stated that it has identified the root cause of the recent security incident and deployed patches for unaffected wallets, and is about to resume normal operations. SecondFi disclosed that there were four instances of funds being transferred out during the incident, three of which were carried out by external attackers, resulting in approximately 16 million ADA being transferred from 374 addresses. To mitigate further losses during the ongoing attack, SecondFi initiated an emergency transfer, moving approximately 129 million ADA to an independent third-party escrow institution for safekeeping, and has engaged an external accounting firm to conduct a special audit to facilitate subsequent verification and return of assets to affected addresses.
SecondFi: Security incident affects approximately 16 million ADA; issue stems from web wallet generation software.
PANews reported on June 24th that SecondFi, a Cardano ecosystem project, released a security incident update, stating that the root cause has been identified and the issue is limited to its native Cardano web wallet generation software. The initial estimate of the total impact is approximately 16 million ADA (currently worth about $2.42 million). The team has completed on-chain analysis and is conducting an independent technical review with a blockchain security company to verify the results. The platform remains in security maintenance mode, and a full snapshot of the balance has been taken. For affected users, the team has taken extraordinary measures to protect their remaining assets and will strive to compensate them.
SecondFi: A small number of Cardano wallets have been found to be affected by security issues, and the platform has entered maintenance mode.
According to Foresight News , SecondFi, a custodial financial platform, tweeted that it had discovered a security issue affecting a small number of Cardano wallets. The issue has been brought under control, and affected functionality has been temporarily suspended. To protect users, SecondFi has temporarily entered maintenance mode, suspending all front-end interactions, and users are temporarily unable to trade. The team is working diligently to restore platform functionality.
SecondFi: On-chain recovery solution is more complex than expected; recovery time may exceed two weeks.
Odaily Odaily reports that Cardano wallet service provider SecondFi has released an update on the security incident recovery, stating that EMURGO has established an asset recovery fund to return assets to users affected by the attack. SecondFi stated that it has taken emergency measures to protect and restore access to some assets, and the team is discussing a suitable custody mechanism with Intersect to ensure the safe return of the relevant assets to users. In addition, SecondFi is collaborating with a Cardano community-led working group to advance the on-chain recovery plan. Due to the greater complexity of the recovery plan than previously anticipated, the overall recovery time may exceed the initial estimate of two weeks.
SecondFi released an update on the progress of user asset recovery: the entire process may take longer than the previously estimated two weeks.
PANews reported on June 29th that SecondFi released an update on its recovery progress, focusing on the return of user assets, secure asset migration, and on-chain recovery solutions. Regarding the assets stolen by the attackers, Emurgo has injected funds into a dedicated asset recovery wallet to return funds to affected users. Assets protected through SecondFi's emergency response are currently safe and available, and the team is negotiating custody and return mechanisms with IntersectMBO. SecondFi stated that it will work with the Cardano community working group to advance the on-chain recovery solution, but the entire process may exceed the previously estimated two-week period. The official statement reiterated that they will not solicit private keys, seed phrase, or send private messages to users in any form; users should only submit support tickets through the official website's support channels.