SecondFI Unveils Asset Recovery Tool After $2M Cardano Wallet Exploit
SecondFI has developed an asset recovery tool following a security incident in June that saw $2 million exploited from Cardano wallets. The company's software signer contained a deterministic nonce derivation flaw, allowing attackers to mathematically reconstruct private keys.
Before releasing the tool publicly, SecondFI is taking a staged approach, with an independent security review of its technology and another audit of the smart contract that will handle the recovery process.
The company has also hired zkSecurity to independently audit its proof-tool repository, which uses zero-knowledge proofs (ZKPs) to allow users to prove control over their Cardano wallets without revealing sensitive information.
According to the audit report, zkSecurity identified two high-severity issues in upstream code, both of which have been fixed by SecondFI. The recovery tool is expected to be launched in the coming weeks once production checks are complete.