SecondFi has renewed its bounty offer to the attacker responsible for stealing 16.1 million Cardano (ADA), urging a voluntary return of the funds. The theft, which occurred between June 21 and June 23, 2026, compromised 374 wallets connected to the platform, with the stolen ADA valued at approximately $2.5 million at the time.
In a public statement, the team said: “Our standing offer remains open. We encourage the party involved to reach out through the contact provided below. A voluntary return continues to be the cleanest, most direct path to a resolution for everyone involved.” Secure communication channels remain available for negotiations regarding full recovery.
Following the breach, engineers managed to prevent further losses by transferring an additional 129 million ADA from vulnerable accounts to an independent custodian. SecondFi, alongside the Cardano Foundation and Input Output, has now launched a structured recovery plan. The initial phase focuses on verifying claims from affected users, while subsequent steps will provide tools to safely export remaining assets. A final compensation portal is planned to use zero‑knowledge proofs, allowing users to prove eligibility without exposing sensitive personal data.
Blockchain security investigators at Groom Lake reported that transaction patterns and operational behavior during the exploit closely resemble techniques previously linked to North Korea’s Lazarus Group, although official attribution has not been confirmed. Despite the sophistication of the attack, the Cardano core network continued to operate normally throughout the incident, highlighting that vulnerabilities were specific to the service provider and not the underlying protocol.