en

16.1 Million Cardano (ADA) Exploit: SecondFi Maps Out How It Will Return Stolen Funds

image
rubric logo Security
like buy 3

The developers of the Cardano wallet SecondFi have officially presented a step-by-step roadmap for dealing with the consequences of the June hack. The project is permanently winding down its regular operations and will not return to normal service. All of the team's resources are now focused on one task: safely withdrawing the remaining assets and distributing compensation.

To return funds to affected users, the developers have decided to set a technological precedent. Together with Input Output Group and the Cardano Foundation, they are launching the first Web3 compensation tool based on zero-knowledge proofs.

3 stages of recovery: Inside SecondFi's new $ADA refund roadmap

For those who missed it, in June 2026, hackers stole 16.1 million $ADA, worth about $2.5 million, from 374 SecondFi wallets by exploiting a vulnerability in the Android version of the app. The attack, which involved the Lazarus Group, allowed the hackers to cryptographically derive users' private keys.

However, the project team managed to save 129 million $ADA by transferring the funds to custodial storage.

The published roadmap is divided into three stages:

  • Claims submission (already available): SecondFi has added a simplified ticket system to its application. Affected users need to update the app to the latest version and submit a claim.
  • Migration tool (mid-August): A special utility will automatically withdraw users' assets. It will unstake $ADA and transfer the coins, tokens and NFTs to any other Cardano wallet selected by the user. Importantly, users should not delete their SecondFi wallet or uninstall the application at this stage, as doing so could complicate the recovery process. The tool has already been developed and is currently undergoing an external security audit.
  • ZK refund portal (early September): This is the roadmap's main technical solution. The zero-knowledge-proof-based portal will allow affected users to prove that they owned the compromised wallets and claim compensation without revealing their seed phrases or private keys. The tool will undergo cryptographic audits and testing throughout August.

Beware of phishing

Scammers are already taking advantage of the project's closure. They are creating fake browser extensions and contacting users through private messages while pretending to be customer support representatives.

Important Security Reminder

1. SecondFi will NEVER request private keys, recovery phrases, or wallet credentials, and we will never DM or email you first. Do not accept links from anyone, including people claiming to be SecondFi team members, support, or partners. If you receive…

— SecondFi (@secondfiapp) July 27, 2026

The team has reminded users that SecondFi never contacts them first. The only safe extension is available through the Chrome Web Store and carries a blue verification badge. All links should be checked exclusively through SecondFi's official website.