SecondFi says it will permanently wind down normal operations after a June 2026 hack that drained 16.1 million ADA from user wallets. The Cardano wallet project has published a recovery roadmap centered on withdrawing remaining assets and compensating affected users rather than restoring the service.

Shutdown after June breach

According to the project, the attack hit the Android version of the wallet in June 2026. Hackers exploited a vulnerability that let them cryptographically derive users’ private keys, leading to losses from 374 SecondFi wallets. The stolen amount totaled 16.1 million ADA, which the source article said was worth about $2.5 million at the time.

The report also links the attack to the Lazarus Group. SecondFi said that, despite the breach, its team was able to move 129 million ADA into custodial storage, preserving those assets from the attackers.

Recovery effort becomes sole focus

SecondFi said it will not resume business as usual. Instead, the team is reallocating all resources to handling the aftermath of the exploit. Its stated priorities are to secure withdrawals of the remaining assets and organize compensation for users affected by the theft.

That marks a full strategic shift for the wallet project. Rather than attempting to relaunch the product while recovery is under way, the company says the recovery process itself is now the only mission.

ZK-based compensation tool

As part of that plan, SecondFi says it is working with Input Output Group and the Cardano Foundation on what it describes as the first Web3 compensation tool built on zero-knowledge proofs. The goal is to return funds to impacted users through a mechanism designed for the reimbursement process.

The source article says the project has laid out a step-by-step roadmap, though it does not detail each stage in full. What is clear from the announcement is that the refund process will rely on a new technical framework rather than a standard claims system.

Broader implications

The case highlights both the scale of the exploit and the unusual recovery structure now being proposed. The June attack affected hundreds of wallets and forced SecondFi to abandon ordinary operations altogether. At the same time, the project says it preserved a far larger pool of assets, with 129 million ADA moved to custodial storage after the breach.

The next phase depends on how the compensation system is implemented and how affected users are processed under the recovery roadmap. For now, SecondFi’s public position is that the wallet is shutting down in practical terms while it concentrates on reimbursement and withdrawals.

Source: u.today