The team behind the Cardano wallet SecondFi has announced a plan to address the aftermath of the June hack. They’ve decided to shut down the wallet permanently and won’t be restoring its services. Currently, all efforts are concentrated on securely withdrawing remaining funds and compensating affected users.
To reimburse users impacted by the issue, the developers are pioneering a new technology. They’ve partnered with Input Output Group and the Cardano Foundation to create the first compensation tool for Web3 that uses zero-knowledge proofs, a method that enhances privacy and security.
3 stages of recovery: Inside SecondFi’s new ADA refund roadmap
In June 2026, hackers stole $2.5 million worth of ADA (about 16.1 million coins) from 374 wallets on the SecondFi app. The hackers, linked to a group called Lazarus, took advantage of a weakness in the Android version of the app to access users’ private keys and steal their funds.
Coinbase CEO Rejects ‘Pivot to AI’ Narrative
Zcash (ZEC), XRP, Shiba Inu (SHIB) and Bitcoin (BTC) Price Analysis for July 26: Liquidity Chooses Wrong Direction
Fortunately, the project team saved 129 million ADA by moving the funds into secure custody.
The published roadmap is divided into three stages:
- Claims submission (already available): SecondFi has added a simplified ticket system to its application. Affected users need to update the app to the latest version and submit a claim.
- Migration tool (mid-August): A special utility will automatically withdraw users’ assets. It will unstake ADA and transfer the coins, tokens and NFTs to any other Cardano wallet selected by the user. Importantly, users should not delete their SecondFi wallet or uninstall the application at this stage, as doing so could complicate the recovery process. The tool has already been developed and is currently undergoing an external security audit.
- ZK refund portal (early September): This is the roadmap’s main technical solution. The zero-knowledge-proof-based portal will allow affected users to prove that they owned the compromised wallets and claim compensation without revealing their seed phrases or private keys. The tool will undergo cryptographic audits and testing throughout August.
Beware of phishing
Now that the project has ended, scammers are trying to trick people. They’re making fake browser add-ons and posing as support staff to reach out through direct messages.
Important Security Alert!
Please remember that SecondFi will *never* ask for your private keys, recovery phrase, or wallet login details. We also won’t contact you first through direct messages or email. Be cautious of links from anyone – even if they claim to be part of the SecondFi team, support staff, or a partner. If you receive…
— SecondFi (@secondfiapp) July 27, 2026
Our team wants to remind you that SecondFi will *never* reach out to you directly first. For your safety, only use the extension available in the Chrome Web Store – look for the blue checkmark to make sure it’s legitimate. Always double-check any links by visiting the official SecondFi website.
2026-07-27 16:35