SecondFI Unveils Asset Recovery Tool After June Security Incident
SecondFI, a self-custody neofinance platform, has developed an asset recovery tool to help users affected by its June security incident. The $2 million exploit was caused by a deterministic nonce derivation flaw in its software signer, which allowed attackers to mathematically reconstruct private keys from public blockchain data.
The company is taking a staged approach to ensure the recovery mechanism's security before releasing it publicly. To achieve this, SecondFI has commissioned an independent security review of the technology behind it and plans to conduct another audit of the smart contract that will handle the recovery process.
SecondFI has also hired zkSecurity to independently audit its proof-tool repository, which uses zero-knowledge proofs (ZKPs) to allow affected users to prove control over their Cardano wallets without revealing sensitive information. The system is optimized for local use in a web browser, reducing the risk of data breaches.
The security review identified two high-severity issues in upstream code, which have since been fixed. However, two low-severity issues remain open and are not considered practically exploitable. SecondFI expects to launch the asset recovery tool in the coming weeks once the recovery smart contract audit is complete and production checks are finalized.