The Cardano‑focused platform SecondFi said it will cease operations after a security breach that resulted in the loss of roughly 2.6 million ADA. The exploit was traced to a flaw in the service’s wallet infrastructure, which allowed an attacker to drain funds before the issue could be contained.
According to the wire report, the theft occurred earlier this year and prompted an immediate investigation. While the exact technical details of the wallet bug have not been disclosed publicly, the team acknowledged that the vulnerability was rooted in the way private keys were managed within the platform’s custodial architecture.
Users who had assets on the platform were told that recovery tools would be released within weeks of the incident. However, those tools have yet to materialize, leaving many holders uncertain about the fate of their ADA. The delay has fueled frustration in the community and raised questions about the project’s ability to execute a timely remediation.
The shutdown underscores the ongoing risks associated with custodial services on proof‑of‑stake networks, where a single point of failure can expose large token holdings. Security researchers have pointed to the incident as a reminder that rigorous code audits and multi‑signature safeguards are essential, especially for platforms handling significant volumes of native assets.
SecondFi’s founders stated they are cooperating with relevant authorities and will provide a final update once the wind‑down process is complete. In the meantime, affected users are advised to monitor official channels for any forthcoming guidance on asset recovery.