SecondFi, a Cardano wallet service, is closing operations following a security breach that resulted in the theft of 16.1 million ADA, valued at approximately $2.4 million. The breach exploited a flaw in SecondFi's transaction signing software, allowing attackers to extract private key material from transaction data on the Cardano blockchain. Despite patching the vulnerability and securing 129 million ADA, SecondFi will not resume operations. The Cardano network itself remained secure, and hardware wallet users were unaffected. Groom Lake, a blockchain intelligence firm, identified the primary attacker as sophisticated and well-funded, with potential links to North Korea's Lazarus Group, though this remains unconfirmed. SecondFi plans to release wallet export tools in early August and a zero-knowledge recovery portal later that month. EMURGO has established an asset recovery wallet, but no distribution date has been set.