XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Markets
● Markets

SecondFi Shuts Down After $2.6M ADA Breach Linked to Lazarus Group

EMURGO announces complete liquidation of SecondFi wallet after hackers stole 16.1 million Cardano tokens, with investigation pointing to North Korean state-sponsored cybercriminals.

JM
by Jacob Marquez · Markets Desk
Published July 30, 2026 · 2 min read

SecondFi Breached: 16.1 Million ADA Stolen in June Attack

The Cardano-focused cryptocurrency wallet SecondFi, formerly known as Yoroi Wallet and operated by EMURGO, experienced a significant security breach between June 21 and June 23, 2026. According to SecondFi’s official statement, attackers successfully compromised 374 digital wallets on the platform, making off with 16.1 million ADA tokens valued at approximately $2.4 million to $2.6 million at the time of the theft. While this represents a substantial loss for affected users, SecondFi’s technical team responded swiftly to prevent further damage, successfully securing an additional 129 million ADA that remained at risk and transferring these assets to an independent custodian for safekeeping.

Investigation Links Attack to Lazarus Group

When independent analytics agency Groom Lake joined the investigation into the breach, researchers began to piece together the full scope of the attack. They discovered specific digital markers embedded within the transactions and patterns of activity related to the compromise. These markers were reportedly consistent with known methods historically employed by Lazarus Group, the state-sponsored cybercriminal organization linked to North Korea. The identification of these signatures raises significant concerns about the escalating sophistication of nation-state-backed cyber operations targeting cryptocurrency platforms. Given the extremely low likelihood of recovering assets stolen by such adversaries, SecondFi, in collaboration with the Cardano Foundation and Input Output Group, announced a three-stage compensation plan to address the impact on affected users.

EMURGO Announces Project Wind-Down

The severity of the breach, combined with its financial and reputational fallout, proved too substantial for EMURGO to overcome. The company announced the complete wind-down and subsequent liquidation of both the SecondFi and Yoroi Wallet brands, determining that the project had become unviable for continued operations. Nevertheless, SecondFi has maintained an open standing bounty offer for the complete return of stolen assets, urging the party involved to make contact through official channels. The company emphasized that a voluntary return would represent the cleanest and most direct path toward resolving the situation for all parties involved.

The incident demonstrates how nation-state-backed cyber attacks pose a persistent threat to cryptocurrency infrastructure and user confidence across all blockchain ecosystems, including those leveraging digital assets like XRP for cross-border payments and settlements.

Source: SecondFi, via U.Today. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Markets Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.