TL;DR
- SecondFi has renewed its bounty offer to the attacker responsible for stealing 16.1 million ADA, encouraging the full return of the assets while continuing to work with blockchain security researchers.
- Investigators identified behavioral patterns that resemble techniques previously linked to North Korea’s Lazarus Group, although the attribution has not been officially confirmed.
- The Cardano Foundation and Input Output are supporting a phased recovery plan, helping affected users recover remaining assets and preparing a compensation process backed by zero-knowledge proofs.
SecondFi is continuing its recovery efforts after the theft of 16.1 million Cardano (ADA), renewing its invitation for the attacker to return the stolen funds through an active bounty program. The incident remains one of the largest wallet-related security events affecting the Cardano ecosystem in recent months, prompting coordinated action from infrastructure providers and blockchain security specialists.
Our standing offer remains open. We encourage the party involved to reach out through the contact provided below.
A voluntary return continues to be the cleanest, most direct path to a resolution for everyone involved. https://t.co/eYSlJsrIPw
— SecondFi (@secondfiapp) July 30, 2026
SecondFi Cardano (ADA) Recovery Plan Advances
The development team confirmed that its proposal to the attacker remains active, describing a voluntary return of the assets as the fastest path toward resolving the incident. According to the company, secure communication channels remain available for negotiations involving the complete recovery of the stolen ADA.
The breach occurred between June 21 and June 23, affecting 374 wallets connected to the platform. Approximately 16.1 million ADA, valued at around $2.5 million at the time of the exploit, was taken by the attackers. Engineers responded before additional wallets could be compromised, securing another 129 million ADA by transferring those holdings to an independent custodian.
SecondFi, the Cardano Foundation, and Input Output have also introduced a structured recovery strategy. The current phase focuses on verifying claims submitted by affected users. The following stage will provide tools for safely exporting remaining assets, while hardware wallets are recommended for long-term protection. A final compensation portal is expected to rely on zero-knowledge proofs, allowing users to verify claims without exposing sensitive personal information.


Security Investigation Points To Sophisticated Threats
Independent blockchain investigators from Groom Lake reported that transaction patterns and operational behavior observed during the exploit resemble techniques previously associated with the Lazarus Group. While these similarities have drawn attention across the cybersecurity sector, blockchain attribution remains technically challenging, and investigators continue analyzing available evidence.
The attack also highlights a broader cybersecurity trend across the digital asset industry. Sophisticated threat actors increasingly target wallet providers, bridges, and decentralized finance infrastructure instead of blockchain protocols themselves. Cardano’s core network continued operating normally throughout the incident, reinforcing the distinction between protocol-level security and vulnerabilities affecting individual service providers.





Be the first to comment