The team behind SecondFi, a cryptocurrency wallet platform focused on Cardano, released a renewed call to the hacker responsible for breaching its systems in June. The developers confirmed that their original bounty proposal remains valid, offering incentives in exchange for the full return of stolen assets.
Official statement and recovery efforts
SecondFi addressed the attacker directly in an official statement, urging communication through designated channels. The company emphasized that a voluntary return of the pilfered funds would provide the fastest route to resolving the situation for everyone involved.
SecondFi reaffirmed its standing offer, calling on the responsible party to reach out via official channels and stating that voluntary action represents the most straightforward path for all parties.
SecondFi, alongside the Cardano Foundation and Input Output Group, recognized that the odds of hearing back from the suspected attacker—identified by some as Lazarus Group—remain minimal. In response, the three organizations have initiated a structured three-stage compensation program for affected users.
Compensation timeline and user instructions
The compensation plan involves several key phases. Currently, the team is collecting, verifying, and processing claims submitted by those impacted by the breach. This process will continue through late July. By mid-August 2026, SecondFi plans to release tools that will allow users to securely export any remaining assets to external platforms. Users are advised to consider moving their holdings into hardware wallets for added security.
A further step is scheduled for early September 2026, when an automated compensation portal leveraging zero-knowledge proofs will go live. This portal is intended to streamline reimbursement by verifying user claims while protecting sensitive data.
Mini dictionary: Zero-knowledge proofs, a cryptographic method that allows one party to prove to another that a statement is true without revealing any specific details about the statement itself. This technology is widely used in blockchain applications for enhancing privacy and security.
| Compensation Stage | Date | Key Action |
|---|---|---|
| Claims processing | Late July 2026 | Collection and verification of user claims |
| Asset export tools | Mid-August 2026 | Secure export of assets to third-party platforms |
| Automated compensation | Early September 2026 | Launch of zero-knowledge proof-powered portal |
Background of the incident
The security incident occurred between June 21 and June 23, 2026. Attackers breached the SecondFi platform—previously known as Yoroi Wallet by blockchain infrastructure company EMURGO—compromising 374 individual wallets. The hack resulted in the theft of 16.1 million Cardano (ADA) tokens, valued at approximately $2.4 million to $2.6 million at the time.
Further losses were prevented by a rapid response from SecondFi’s technical team, who managed to secure another 129 million ADA, moving these funds to an independent custodian immediately to protect them from further compromise.
EMURGO’s decision and aftereffects
Following the breach’s far-reaching financial and reputational consequences, EMURGO’s leadership opted for decisive action. The company announced a total discontinuation and subsequent liquidation of both the SecondFi and Yoroi brands, citing that continuation of the service was no longer viable.
This move marked the end of SecondFi’s journey, with the focus now shifting entirely toward compensating and securing impacted users.




