EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

SecondFi unveils three-phase ADA compensation plan after June hacking

2026-07-28 00:12:45
Bookmark

SecondFi announces ADA compensation plan to address the impact of June security incidents.

Cardano wallet service provider SecondFi recently released a detailed user compensation plan for security breaches that occurred in June 2026. The company confirmed that it will permanently cease regular operations and shift all resources to asset withdrawals and user compensation work.

The first Web3 compensation tool equipped with zero-knowledge proof

SecondFi has partnered with the Input Output Group and the Cardano Foundation to jointly launch the first Web3 compensation tool using zero-knowledge proof technology. The mechanism is designed to allow eligible users to safely receive funds without having to disclose sensitive information such as seed phrases or private keys.

SecondFi was originally committed to providing a secure and user-friendly Cardano wallet experience, but suffered a carefully planned attack in June that severely affected its operations and user trust.

Zero-knowledge proof is a cryptographic technique that allows a party to prove that it has specific information without revealing the information itself. In this compensation plan, this method will be used to verify the ownership of the affected wallet, thereby completing the compensation payment.

June attack details and recovery work

The June 2026 attack resulted in the theft of 16.1 million ADAs from 374 user wallets, worth approximately US$2.5 million. The incident was related to the well-known cybercriminal organization Lazarus Group, which used a security vulnerability in the SecondFi Android app to steal users 'private keys.

Still, the SecondFi team successfully protected 129 million ADAs by moving funds to secure managed wallets, avoiding greater losses during the attack.

Overview of affected assets:

Stolen: 16.1 million ADA (approximately US$2.5 million), involving 374 wallets
Funds successfully protected after theft: 129 million ADA

Three-phase refund roadmap

The roadmap released details the recovery steps. The first stage, for claim submission, has been launched. Affected users need to update the application to the latest version and submit claims through the new work order system interface.

The second phase is scheduled to start in mid-August and involves a migration tool. The tool will unpledge ADA and transfer all assets, including tokens and NFTs, to a user-specified target Cardano wallet. The migration tool is ready and an external security audit is currently underway. Users are advised not to delete SecondFi wallets or uninstall applications during this period to avoid affecting the recovery process.

The third and final phase is expected to be launched in early September and mainly focuses on the zero-knowledge certificate refund portal. The portal will use zero-knowledge proof technology to verify wallet ownership, allowing users to safely receive compensation. The solution will undergo further encryption audits and testing during August.

SecondFi partnered with the Cardano Foundation and the Input Output Group to launch this zero-knowledge proof-based compensation portal that allows users to confirm ownership of damaged wallets and obtain refunds without disclosing sensitive credential information throughout the process.

Security Warnings and User Tips

With SecondFi shutting down regular operations, scammers have tried to take advantage of the situation to commit fraud by distributing fake browser extensions and impersonating customer service personnel through private messages. The team continues to remind users to be alert to these scams.

SecondFi emphasizes that official communication will never proactively contact users. The only legal extension is available through the Chrome Online App Store and comes with a blue verification badge. Users should only access links through the official SecondFi website to avoid being deceived.

Official representatives urged users to ignore unsolicited private messages and directly verify all extensions and communications through official channels.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP