SecondFI Rolls Out Asset Recovery Tool After $2M Cardano Wallet Exploit
SecondFI, a self-custody neofinance platform, has developed an asset recovery tool following a June $2 million Cardano wallet exploit. The company is taking a staged approach to ensure the security of the recovery mechanism before making it publicly available.
The exploit was caused by a deterministic nonce derivation flaw in SecondFI's software signer, allowing attackers to mathematically reconstruct private keys from public blockchain data after affected addresses signed transactions.
To address this issue, SecondFI commissioned an independent security review and hired zkSecurity to audit its proof-tool repository. The audit identified two high-severity issues in upstream code, which were promptly fixed by SecondFI.