SecondFi has renewed a bounty aimed at recovering funds stolen in a June exploit that drained 16.1 million ADA from the Cardano ecosystem. The team says the breach — caused by a key-generation vulnerability — impacted 374 wallets and remains the focus of an ongoing recovery effort. Key facts - Stolen: 16.1 million ADA. - Affected wallets: 374. - Containment: SecondFi says it secured about 129 million ADA during containment actions. - Status: SecondFi confirmed it will not resume normal operations and is concentrating on recovery, claims and containment. - Attribution: Security researchers at Groom Lake reported seeing activity that resembled techniques linked in past reporting to North Korea’s Lazarus Group — but that attribution is unconfirmed. Researchers stress that behavioral similarity is not proof of identity. Why this matters A key-generation flaw is one of the most damaging kinds of wallet or protocol failures. If private keys, seeds or signing paths are generated in weak or predictable ways, users can lose funds even without clicking a malicious link or approving a bad transaction. Unlike a typical smart contract bug, this type of failure undermines the fundamental trust of a platform: users can no longer rely on the basics of wallet security, which makes rebuilding credibility exceptionally difficult. Containment versus loss SecondFi’s claim of securing 129 million ADA during containment is significant. Headlines tend to focus on what vanished, but preventing a larger collapse matters too. Still, for those whose assets were taken, the immediate concern is recovery — and a renewed bounty is intended to create an incentive for the attacker to return funds. Bounties can succeed, fail, or produce partial recoveries; outcomes hinge on fund traceability, the ability of exchanges and bridges to freeze or block movement, law enforcement involvement, and whether the attacker perceives a bounty as a safer option than keeping or laundering the assets. On attribution and caution Attributing cyberattacks is notoriously hard. While patterns of behavior or reused techniques can point to known groups, methods can be copied and infrastructure repurposed. Responsible reporting therefore treats observed similarities as leads, not confirmations. In this case, researchers observed Lazarus-like techniques, but there is no official confirmation linking the incident to that group. What this means for Cardano DeFi The incident is a reminder that chain-level security is only part of the story. Application-layer issues — key management, wallet generation, custody assumptions and operational controls — are critical. For Cardano applications handling growing sums of ADA, stronger security expectations are necessary: rigorous audits, independent key-generation reviews, penetration testing, incident response planning, and transparent communication are essential for moving from experimental apps to infrastructure users can trust. What’s next The renewed bounty keeps the door open for recovered funds, but the case remains unresolved. The best outcome would be a negotiated return of assets; the harder path is a long tracing, sanctions and enforcement process. Until funds are returned or a formal recovery plan is completed, users should treat the matter with caution. Source and credits This report is based on SecondFi incident and recovery materials and the platform’s renewed bounty update, as published on Support. Written by the News Desk; edited by Samuel Rae. Read more AI-generated news on: undefined/news