TL;DR
SecondFi is continuing its recovery efforts after the theft of 16.1 million Cardano (ADA), renewing its invitation for the attacker to return the stolen funds through an active bounty program. The incident remains one of the largest wallet-related security events affecting the Cardano ecosystem in recent months, prompting coordinated action from infrastructure providers and blockchain security specialists.
Our standing offer remains open. We encourage the party involved to reach out through the contact provided below.
— SecondFi (@secondfiapp) July 30, 2026
A voluntary return continues to be the cleanest, most direct path to a resolution for everyone involved. https://t.co/eYSlJsrIPw
The development team confirmed that its proposal to the attacker remains active, describing a voluntary return of the assets as the fastest path toward resolving the incident. According to the company, secure communication channels remain available for negotiations involving the complete recovery of the stolen ADA.
The breach occurred between June 21 and June 23, affecting 374 wallets connected to the platform. Approximately 16.1 million ADA, valued at around $2.5 million at the time of the exploit, was taken by the attackers. Engineers responded before additional wallets could be compromised, securing another 129 million ADA by transferring those holdings to an independent custodian.
SecondFi, the Cardano Foundation, and Input Output have also introduced a structured recovery strategy. The current phase focuses on verifying claims submitted by affected users. The following stage will provide tools for safely exporting remaining assets, while hardware wallets are recommended for long-term protection. A final compensation portal is expected to rely on zero-knowledge proofs, allowing users to verify claims without exposing sensitive personal information.

Independent blockchain investigators from Groom Lake reported that transaction patterns and operational behavior observed during the exploit resemble techniques previously associated with the Lazarus Group. While these similarities have drawn attention across the cybersecurity sector, blockchain attribution remains technically challenging, and investigators continue analyzing available evidence.
The attack also highlights a broader cybersecurity trend across the digital asset industry. Sophisticated threat actors increasingly target wallet providers, bridges, and decentralized finance infrastructure instead of blockchain protocols themselves. Cardano’s core network continued operating normally throughout the incident, reinforcing the distinction between protocol-level security and vulnerabilities affecting individual service providers.