- 3 levels of restoration: Inside SecondFi’s new ADA refund roadmap
- Watch out for phishing
The builders of the Cardano pockets SecondFi have formally introduced a step-by-step roadmap for coping with the implications of the June hack. The mission is completely winding down its common operations and won’t return to regular service. The entire crew’s assets at the moment are targeted on one process: safely withdrawing the remaining property and distributing compensation.
To return funds to affected customers, the builders have determined to set a technological precedent. Along with Enter Output Group and the Cardano Basis, they’re launching the primary Web3 compensation device primarily based on zero-knowledge proofs.
3 levels of restoration: Inside SecondFi’s new ADA refund roadmap
For many who missed it, in June 2026, hackers stole 16.1 million ADA, value about $2.5 million, from 374 SecondFi wallets by exploiting a vulnerability within the Android model of the app. The assault, which concerned the Lazarus Group, allowed the hackers to cryptographically derive customers’ non-public keys.
Coinbase CEO Rejects ‘Pivot to AI’ Narrative
Zcash (ZEC), XRP, Shiba Inu (SHIB) and Bitcoin (BTC) Value Evaluation for July 26: Liquidity Chooses Flawed Course
Nevertheless, the mission crew managed to avoid wasting 129 million ADA by transferring the funds to custodial storage.
The printed roadmap is split into three levels:
- Claims submission (already accessible): SecondFi has added a simplified ticket system to its utility. Affected customers must replace the app to the newest model and submit a declare.
- Migration device (mid-August): A particular utility will robotically withdraw customers’ property. It can unstake ADA and switch the cash, tokens and NFTs to some other Cardano pockets chosen by the consumer. Importantly, customers shouldn’t delete their SecondFi pockets or uninstall the appliance at this stage, as doing so might complicate the restoration course of. The device has already been developed and is presently present process an exterior safety audit.
- ZK refund portal (early September): That is the roadmap’s important technical answer. The zero-knowledge-proof-based portal will permit affected customers to show that they owned the compromised wallets and declare compensation with out revealing their seed phrases or non-public keys. The device will bear cryptographic audits and testing all through August.
Watch out for phishing
Scammers are already making the most of the mission’s closure. They’re creating faux browser extensions and contacting customers by means of non-public messages whereas pretending to be buyer assist representatives.
The crew has reminded customers that SecondFi by no means contacts them first. The one secure extension is out there by means of the Chrome Net Retailer and carries a blue verification badge. All hyperlinks must be checked completely by means of SecondFi’s official web site.

