SecondFi has renewed its bounty offer to the attacker behind a June exploit that drained 16.1 million ADA, extending an effort to recover funds lost in one of the more serious recent incidents in the Cardano ecosystem. According to the project’s validated notes, the breach affected 374 wallets.

SecondFi said the incident was tied to a key-generation vulnerability rather than a more typical user-side mistake such as phishing or a malicious approval. The team also said it managed to secure 129 million ADA during containment, but confirmed that normal operations will not resume.

Recovery effort continues

The renewed bounty underscores that SecondFi’s immediate priority remains the stolen funds. Bounty offers are sometimes used after major exploits in the hope that an attacker will return assets in exchange for keeping an agreed portion, but they do not guarantee any recovery.

In this case, the headline loss remains 16.1 million ADA. At the same time, SecondFi has pointed to the 129 million ADA it says was secured during containment as evidence that the response prevented a larger outcome. The remaining focus is on tracing and recovering the missing assets.

A flaw at the security foundation

The most significant technical detail disclosed so far is the reported key-generation vulnerability. Failures in key generation are especially serious because they can undermine the basic security assumptions behind wallets or signing systems.

That distinguishes the incident from attacks that depend mainly on user error. If the weakness was embedded in how keys were created, affected users could have been exposed even without clicking a malicious link or knowingly approving a harmful transaction. That kind of flaw can make recovery and trust rebuilding much harder.

Researchers cite Lazarus-like behavior, without confirmation

Security researchers at Groom Lake reportedly observed behavior that resembled techniques previously associated with North Korea’s Lazarus Group. However, no official confirmation of attribution has been provided.

That distinction remains important. Similar tradecraft or transaction patterns can raise suspicion, but resemblance alone is not proof of identity. For now, the available information supports only the narrower claim that analysts saw overlaps with known methods, not that the attacker has been definitively identified.

SecondFi shifts from restart to containment

SecondFi has now made clear that it will not resume normal operations. That changes the shape of the story from a possible relaunch after remediation to a narrower effort centered on containment, communication, and recovery.

For affected users, that means the main confirmed path forward is no longer a return to business as usual. Instead, the project’s remaining role is tied to safeguarding protected funds, continuing outreach tied to the bounty, and providing clarity around the aftermath of the exploit.

What is confirmed now

At this stage, the confirmed facts are limited but significant: 16.1 million ADA was stolen in June, 374 wallets were affected, the exploit was linked by SecondFi to a key-generation vulnerability, and the team says 129 million ADA was secured during containment.

The next confirmed step is the ongoing recovery push through the renewed bounty offer. Beyond that, attribution remains unconfirmed, and SecondFi’s own position is that normal operations will not return.

Source: bitcoinist.com