SecondFi has renewed a bounty aimed at recovering 16.1 million ADA stolen in a June exploit, as the project shifts into full recovery-and-containment mode rather than trying to resume normal operations. What happened - The exploit, which SecondFi says affected 374 wallets, stemmed from a key-generation vulnerability — one of the most severe classes of wallet/protocol failures. If private keys, seeds, or signing paths are generated in a weak or predictable way, users can lose funds even without falling for phishing or approving malicious transactions. That makes these failures particularly damaging to user trust. - SecondFi reports it secured 129 million ADA during containment efforts, but the 16.1 million ADA taken in the breach remains the focus of recovery work. - The team has renewed a bounty offer to the attacker as an incentive to return the funds. Bounties can succeed in some cases, but they are no guarantee: attackers may ignore offers, launder funds, negotiate partial returns, or be deterred if the funds are hard to trace or if exchanges and bridges block movement. Attribution and caution - Security researchers at Groom Lake observed behavior in the attack that resembles techniques previously linked to North Korea’s Lazarus Group. However, Groom Lake’s note — and SecondFi’s materials — explicitly stop short of a formal attribution. Similar tactics or infrastructure reuse do not constitute proof of identity, and analysts emphasize that techniques can be copied or reused by other actors. Operational aftermath - SecondFi has confirmed it will not return to normal operations. Rather than a comeback story, the incident is now focused on asset recovery, claims processing, communications with affected users, and ensuring remaining secured funds remain protected. - This outcome signals the depth of the credibility problem that follows a key-generation failure: fixes and audits that might suffice after a smart-contract bug are less likely to restore trust when the core of wallet security is questioned. Why this matters for Cardano DeFi - The incident is a reminder that chain security alone cannot compensate for weak application-layer practices. Wallet key generation, custody assumptions, operational controls, independent audits, and clear incident-response plans are essential as DeFi applications handle larger sums. - For users and builders: rigorous key-generation reviews, third-party testing, and transparent communications aren’t optional if projects want to be treated as reliable infrastructure. What’s next - The renewed bounty keeps a path open for a negotiated return, but the recovery could also turn into a prolonged tracing and enforcement effort. Outcomes typically depend on how traceable the stolen ADA is, how effectively exchanges and bridges can act, and whether law enforcement intervenes. - Until funds are returned or a formal recovery plan is completed, the situation remains unresolved. A negotiated return would be the best short-term outcome for affected users; a lengthy tracing process would be the most difficult. For full details and claims guidance, consult SecondFi’s official support channels. This report is based on SecondFi’s incident and recovery materials, including the renewed bounty update. Written by the News Desk; edited by Samuel Rae. Read more AI-generated news on: undefined/news