SecondFi Pleads for Return of Stolen 16.1M ADA Tokens in North Korean Hack
The Cardano-focused cryptocurrency wallet SecondFi is once again appealing to the hacker who breached their platform in June. The developers are reiterating that their official bounty offer remains in effect, urging the party involved to contact them through listed channels.
SecondFi emphasized that a voluntary return of the stolen assets would be the cleanest and most direct path towards resolving the situation for all parties.
In an interesting twist, researchers from Groom Lake discovered specific digital markers in the transactions and actions of one of the participants in the attack. These markers reportedly match methods used by the state-sponsored North Korean cybercrime group Lazarus Group.
Since the likelihood of receiving a response from Lazarus Group is extremely low, SecondFi has launched a three-stage compensation plan with the Cardano Foundation and Input Output Group:
The first stage, currently in progress, involves collecting, verifying, and processing official claims submitted by affected customers. The second stage, scheduled for mid-August 2026, will see the release of tools for securely exporting surviving assets to third-party platforms. Users are advised to move their funds to hardware wallets.
The third and final stage, set for early September 2026, will be the launch of an automated compensation portal powered by zero-knowledge proofs.