SecondFi to Shut Down Cardano Wallet and Launch Three-Stage ADA Recovery Plan
Key Takeaways
- •SecondFi is shutting down its Cardano wallet rather than restoring normal operations after the June security breach.
- •The June 2026 exploit affected 374 wallets and resulted in the theft of 16.1 million ADA valued at about $2.5 million.
- •SecondFi said it secured 129 million ADA by moving unaffected assets into custodial storage before additional funds could be stolen.
- •Input Output Group and the Cardano Foundation are supporting a zero-knowledge proof compensation system for verifying wallet ownership without exposing private keys or seed phrases.
- •SecondFi warned users not to delete the app or wallet before migration and advised them to verify recovery links through its official website.

SecondFi will permanently shut down its Cardano wallet and redirect its remaining resources toward asset recovery and compensation for affected users after a June security breach.
The team has outlined a three-stage ADA recovery and migration process intended to help users withdraw remaining assets safely instead of restoring normal wallet operations. Developers said they have secured 129 million ADA, opened a claims portal, and are preparing audited migration tools to protect user funds that were not taken in the attack.
According to SecondFi, the recovery effort is being supported by Input Output Group and the Cardano Foundation. The organizations are developing a zero-knowledge proof compensation system that will allow users to verify ownership of compromised wallets without revealing seed phrases or private keys. That approach is central to the recovery process because seed phrases and private keys control wallet access, and exposing them during a refund claim would create another security risk.
The plan follows a June 2026 exploit that affected 374 SecondFi wallets. Attackers stole 16.1 million ADA, valued at about $2.5 million, after exploiting a vulnerability in the Android version of the wallet. Developers linked the incident to the Lazarus Group and said the flaw enabled attackers to derive users’ private keys.
SecondFi said it prevented additional losses by transferring unaffected assets into custodial storage. The move secured another 129 million ADA before more funds could be stolen.
Recovery plan includes claims, migration, and refunds
SecondFi has already started the first phase of the process through an updated version of its application. The update includes a simplified claims system, and affected users must update the wallet before submitting recovery requests through the built-in portal.
The second phase is scheduled for mid-August, when SecondFi plans to release an automated migration tool. The utility will unstake ADA and move coins, tokens, and NFTs to another Cardano wallet chosen by each user. For users with staked ADA or Cardano-based assets, the migration tool is meant to consolidate the withdrawal process rather than requiring separate manual steps for each asset type.
Developers also warned users not to uninstall the application or delete their existing wallet before completing the migration process. SecondFi said removing the app or wallet too early could make recovery more difficult.
The final phase is expected in early September with the launch of a zero-knowledge proof refund portal. SecondFi said the platform will undergo independent cryptographic audits throughout August before it becomes available to users.
The team also issued phishing warnings related to the shutdown and recovery process. SecondFi said it does not contact users through private messages and advised users to download browser extensions only from the verified Chrome Web Store listing. It also urged users to confirm every recovery link through SecondFi’s official website before taking action.