Skip to content
Active Currencies: 21,233
Market Cap: $2.706T
Bitcoin Dominance: 58.45%
24h Market Cap Change: $-0.01

SecondFI reveals asset recovery tool following June’s Cardano wallet exploit

After the exploit, SecondFi is turning to zero-knowledge proofs to help affected users recover their assets securely.

SecondFI reveals asset recovery tool following June's Cardano wallet exploit

SecondFI, a self-custody neofinance platform, has come up with an asset recovery tool after the $2 million exploit that happened in the month of June. The tool is designed to allow users affected by its security incident to recover their assets.

However, the tool is not in full swing yet, as the company is taking a staged approach to make sure the recovery mechanism itself is secure before releasing it publicly.

What’s SecondFI’s plan of action?

For this, SecondFi has commissioned an independent security review of the technology behind it and plans to conduct another audit of the smart contract that will ultimately handle the recovery process.

But before this, SecondFi had already identified that the 374 Cardano wallet exploit was caused by a deterministic nonce derivation flaw in its software signer.

This allowed attackers to mathematically reconstruct private keys from public blockchain data after affected addresses signed transactions.

How is zkSecurity helping SecondFi?

On the 3rd of August 2026, SecondFi hired zkSecurity to independently audit its proof-tool repository. The repository uses zero-knowledge proofs (ZKPs) that allow an affected user to prove that they control a particular Cardano [ADA] wallet credential.

The interesting part here is that the user can prove their control without revealing their seed phrase, private key, or wallet derivation path.

Additionally, the system is optimized to run directly in a web browser. As a result, it allows users to generate proofs locally instead of sending sensitive wallet information to a remote server.

Issues identified and fixed

As of now, according to the audit report, zkSecurity has identified two high-severity issues in upstream code. Notably, SecondFi has fixed both the issues. Meanwhile, zkSecurity has also reviewed and tested the fixes, confirming they have been resolved.

At the same time, the audit also found two low-severity issues in SecondFi’s own repository, which remain open but were assessed as not practically exploitable.

While these issues have not been fixed yet, the findings do not necessarily mean the recovery tool is unsafe.

That said, SecondFi expects the asset recovery tool to be launched in the coming weeks. However, this solely depends on the completion of the recovery smart contract audit and final production checks.


Final Summary

  • SecondFi has commissioned an independent security review of the technology behind it.
  • The firm also hired zkSecurity to independently audit its proof-tool repository. 
Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Ishika Kumari

Journalist

Ishika Kumari is a Crypto Analyst at AMBCrypto, specializing in regulatory developments, market dynamics, and blockchain’s real-world impact. She breaks down complex protocols and legislation into practical, easy-to-understand insights.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.