Introduction

On September 14th, 2026, zkSecurity was commissioned to perform an end-to-end security audit of the recovery flow for SecondFi, which enables users to recover their funds by creating a zero-knowledge proof that they possess a master private key that derives a compromised private key, without revealing the master private key.

In particular, the audit focused on the verifier implementations, the soundness and completeness of the end-to-end recovery flow, as well as the web security of the implementation of the flow in the SecondFi recovery application.

The audit lasted two weeks with two consultants and during the audit, the team found two low-severity issues in the target repositories, which the client has acknowledged and implemented fixes for. The audit team has reviewed the changes with tests and confirmed that both issues were properly fixed.

For the sake of completeness, we also reiterate that we reinvestigated the low-severity finding in the previous audit and reconfirmed that it is not practically exploitable.

Scope

The scope of the audit included the full stack of the SecondFi recovery application in the following repositories: Emurgo/proof-tool at commit 622d584, Emurgo/recovery-claims at commit b2d701c, Emurgo/refund at commit 664e85b, Emurgo/refund_utxo_api at commit 619e49c, secondfi-refund-operator at commit 01ca9ac.

  1. Frontend and backend. The refund, recovery-claims, refund_utxo_api, and secondfi-refund-operator repos contains the frontend and the backend of the SecondFi recovery web application.

  2. In-browser prover. The proof-tool repo contains the prover that is compiled to WebAssembly and runs in the browser. It generates Groth16 proofs for the recovery flow.

  3. Go and Smart Contract Groth16 verifiers. The proof-tool repo contains two verifier implementations for the Groth16 proofs and is implemented in two different languages, Go and Haskell (for Cardano smart contracts).

Summary

On a high-level, the SecondFi recovery web application supports two different recovery flows, the whitehat/friend recovery flow and the blackhat/mixed recovery flow.

The whitehat/friend recovery flow

This flow is for affected SecondFi users whose funds have been transferred to known whitehat/friend addresses. These funds have been attached to the Cardano smart contract in the form of UTXOs that are transferred to a user-chosen address after verifying a Groth16 proof.

Whitehat/Friend Recovery Flow

The blackhat/mixed recovery flow

This flow is similar to the whitehat/friend flow, but it is designed for affected SecondFi users whose funds have been sent to known blackhat addresses or a mixture of blackhat and whitehat addresses. The source of the funds are Secondfi operator addresses that verify Groth16 proofs using the Go verifier and transfer the funds to a user-chosen address after verification.

Blackhat/Mixed Recovery Flow