Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnAISquareMore
SecondFI reveals asset recovery tool following June’s Cardano wallet exploit

SecondFI reveals asset recovery tool following June’s Cardano wallet exploit

AMBCryptoAMBCrypto2026/09/14 21:03
By:AMBCrypto

SecondFI, a self-custody neofinance platform, has come up with an asset recovery tool after the $2 million exploit that happened in the month of June. The tool is designed to allow users affected by its security incident to recover their assets.

However, the tool is not in full swing yet, as the company is taking a staged approach to make sure the recovery mechanism itself is secure before releasing it publicly.

What’s SecondFI’s plan of action?

For this, SecondFi has commissioned an independent security review of the technology behind it and plans to conduct another audit of the smart contract that will ultimately handle the recovery process.

@media only screen and (min-width: 0px) and (min-height: 0px) { div[id^="bsa-zone_1774359638628-7_123456"] { min-height: 50px; transition: min-height 0.3s ease; } } @media only screen and (min-width: 640px) and (min-height: 0px) { div[id^="bsa-zone_1774359638628-7_123456"] { min-height: 90px; } }
AD

But before this, SecondFi had already identified that the 374 Cardano wallet exploit was caused by a deterministic nonce derivation flaw in its software signer.

This allowed attackers to mathematically reconstruct private keys from public blockchain data after affected addresses signed transactions.

How is zkSecurity helping SecondFi?

On the 3rd of August 2026, SecondFi hired zkSecurity to independently audit its proof-tool repository. The repository uses zero-knowledge proofs (ZKPs) that allow an affected user to prove that they control a particular Cardano [ADA] wallet credential.

The interesting part here is that the user can prove their control without revealing their seed phrase, private key, or wallet derivation path.

Additionally, the system is optimized to run directly in a web browser. As a result, it allows users to generate proofs locally instead of sending sensitive wallet information to a remote server.

Issues identified and fixed

As of now, according to the audit report, zkSecurity has identified two high-severity issues in upstream code. Notably, SecondFi has fixed both the issues. Meanwhile, zkSecurity has also reviewed and tested the fixes, confirming they have been resolved.

At the same time, the audit also found two low-severity issues in SecondFi’s own repository, which remain open but were assessed as not practically exploitable.

While these issues have not been fixed yet, the findings do not necessarily mean the recovery tool is unsafe.

That said, SecondFi expects the asset recovery tool to be launched in the coming weeks. However, this solely depends on the completion of the recovery smart contract audit and final production checks.

Final Summary

  • SecondFi has commissioned an independent security review of the technology behind it.
  • The firm also hired zkSecurity to independently audit its proof-tool repository. 
0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!