Loading market data...

SecondFi Renews Bounty After $16.1M Cardano Exploit, Won't Resume Operations

SecondFi Renews Bounty After $16.1M Cardano Exploit, Won't Resume Operations

SecondFi has renewed its bounty offer after a $16.1 million exploit on the Cardano network. The attack, which took place in June, drained 16.1 million ADA from 374 wallets. The company traced the breach to a key-generation vulnerability. It now says it will not resume normal operations, focusing instead on recovery and containment.

The exploit and its impact

The stolen funds — 16.1 million ADA — were taken from wallets that shared a common weakness in how their keys were generated. SecondFi did not name the specific software or service responsible, but investigators said the vulnerability allowed the attacker to derive private keys. All 374 affected wallets were compromised in a single coordinated heist.

The scale of the theft rattled the Cardano community. At current prices, 16.1 million ADA is worth roughly $16.1 million, though the value fluctuates with the market. Users whose wallets were drained have been left without recourse unless the bounty leads to a recovery.

Containment and recovery efforts

During the immediate response, SecondFi managed to secure 129 million ADA — far more than was stolen. The company did not explain how it obtained that amount, but the figure suggests it froze or recovered funds beyond the initial loss. The renewed bounty offer is part of an ongoing effort to track down the remaining stolen assets and identify the perpetrator.

SecondFi originally posted a bounty after the exploit. The renewal signals that the company still believes outside help can make a difference. It has not disclosed the bounty amount or the specific conditions for payment.

Attribution questions

Security researchers at Groom Lake observed behavior during the attack that resembled techniques previously linked to North Korea's Lazarus Group. That group has been tied to a string of crypto heists, including the $620 million Axie Infinity bridge hack. But Groom Lake stopped short of official attribution. No government or law enforcement agency has confirmed Lazarus Group's involvement in this case.

The lack of a firm attribution complicates recovery. Without a named suspect, bounty hunters and investigators have a harder time narrowing their search. SecondFi has not commented on the Lazarus theory.

No return to normal

SecondFi confirmed it will not resume normal operations. The company, which provided some form of financial or security services on Cardano, is now solely focused on recovery and containment. It did not say whether it plans to wind down permanently or eventually relaunch under a different model.

The decision leaves its users in limbo. Those who lost funds are waiting for the bounty to yield results. Those whose wallets were unaffected are left without a service they once relied on. The renewed bounty is open, but the company's future — and the fate of the stolen ADA — remains uncertain.