SecondFi Hacked for $2.5 Million, Redirects Resources to Recovery
A recent hack of SecondFi wallets has led to the theft of approximately $2.5 million in ADA, prompting the project to shut down normal operations and focus on recovery efforts.
The breach occurred in June 2026, when attackers exploited a vulnerability in the Android version of SecondFi's transaction signing software, allowing them to derive users' private keys from transaction data visible on the Cardano blockchain.
A three-stage roadmap has been outlined by SecondFi, Input Output Group, and the Cardano Foundation to return the stolen funds. The first stage involves claims submission, which is currently live in the app, followed by a migration tool that will automatically unstake ADA and transfer coins, tokens, and NFTs to user-selected Cardano wallets.
The most technically ambitious part of the recovery effort is the zero-knowledge proof refund portal, scheduled for early September 2026. This portal will allow affected users to prove they owned compromised wallets without revealing their seed phrases or private keys.