SecondFi:此前安全事件疑与朝鲜 Lazarus Group 有关,8 月将推出资产恢复工具

SecondFi:此前安全事件疑与朝鲜 Lazarus Group 有关,8 月将推出资产恢复工具

2026-07-22 16:24

ChainThink 消息,7 月 22 日,据 SecondFi 披露,其安全事件调查由 EMURGO 委托独立区块链取证机构 Groom Lake 进行。

调查显示,此次事件涉及两名独立攻击者,其中主要攻击者部分指标与朝鲜 Lazarus Group 已知活动存在重叠,相关情况仍在进一步评估;另一名攻击者涉及不同钱包地址,迹象独立于主要攻击。

SecondFi 表示,事件根本原因为钱包软件在生成逐笔交易签名时存在密码学缺陷,理论上可能允许攻击者从公开链上数据中推导受影响钱包的私钥材料。

相关存在缺陷的代码此前曾被未经授权发布至公开 GitHub 仓库,SecondFi 称正持续评估并配合主管机构调查。目前该漏洞已修复,使用修复版本创建的新钱包不受影响。

SecondFi 将关闭 SecondFi 及 Yoroi 钱包,并正在开发基于零知识证明的资产恢复工具,预计于 2026 年 8 月发布;

在此之前,将推出钱包导出功能,供用户将资产迁移至其他钱包。

此前披露信息显示,该事件共发生 4 次资金转出,其中 3 次由外部攻击者实施,约 1600 万枚 ADA 从 374 个地址被转出;

SecondFi 已将约 1.29 亿枚 ADA 转至独立第三方托管机构保管。

Disclaimer: Contains third-party opinions, does not constitute financial advice

Recommended Reading

NVIDIA attracts $85 billion in investor demand during massive bond issuance

06-16
NVIDIA attracts $85 billion in investor demand during massive bond issuance

Ethereum surges over 10% in 24 hours, currently priced at $1,841.31

06-16
Ethereum surges over 10% in 24 hours, currently priced at $1,841.31

Amazon announces a multi-billion dollar investment in Missouri to build a data center campus, expected to create over 400 long-term positions

06-16
Amazon announces a multi-billion dollar investment in Missouri to build a data center campus, expected to create over 400 long-term positions

Binance Platform's SpaceX Perpetual Contract Trading Volume Surpasses $9 Billion, Capturing Over 60% Market Share

06-16
Binance Platform's SpaceX Perpetual Contract Trading Volume Surpasses $9 Billion, Capturing Over 60% Market Share

Binance platform XLM/USDT short-term spike down to $0.17, now recovered to $0.225

06-16
Binance platform XLM/USDT short-term spike down to $0.17, now recovered to $0.225

Trump: The Strait of Hormuz has been fully reopened as of Friday, and all agreements have been signed

06-16
Trump: The Strait of Hormuz has been fully reopened as of Friday, and all agreements have been signed

SlowMist: Aztec Connect Contract Hacked for $2.19 Million Due to ZK-Rollup L1/L2 State Boundary Vulnerability

06-15
SlowMist: Aztec Connect Contract Hacked for $2.19 Million Due to ZK-Rollup L1/L2 State Boundary Vulnerability