SecondFi Builds Recovery Tool After $2 Million Cardano Wallet Exploit
SecondFi, a self-custody neofinance platform, is developing a recovery tool for users affected by a $2 million exploit that struck 374 Cardano wallets in June. Investigators traced the breach to a deterministic nonce derivation flaw in SecondFi's software signer, which allowed attackers to mathematically reconstruct private keys from public blockchain data once affected wallets signed transactions.
Rather than rush a fix to market, SecondFi is taking a staged approach. It commissioned security firm zkSecurity to audit the proof-tool repository behind the recovery system, which uses zero-knowledge proofs so users can verify control of a wallet without exposing their seed phrase, private key, or derivation path. The tool runs in the browser, generating proofs locally rather than sending sensitive wallet data to a remote server.
The audit found two high-severity issues in upstream code, both of which SecondFi has since fixed and zkSecurity has confirmed as resolved. Two low-severity issues remain open in SecondFi's own code but were assessed as not practically exploitable. A further audit of the recovery smart contract is planned before public launch, which SecondFi expects within the coming weeks.