Skip to main content

SecondFi Renews Bounty Push After $16.1M Cardano Exploit

Importance Critical

SecondFi has renewed its bounty offer to the attacker behind a $16.1 million Cardano exploit, as the team continues its recovery effort for 16.1 million ADA stolen in a June incident. The exploit affected 374 wallets and stemmed from a key-generation vulnerability, according to validated notes. SecondFi reported it secured 129 million ADA during containment, but the stolen funds remain the focus. Security researchers at Groom Lake observed behavior resembling techniques previously linked to North Korea’s Lazarus Group, though attribution has not been officially confirmed. SecondFi also confirmed it will not resume normal operations, shifting the story from recovery to containment. The key-generation vulnerability is a critical flaw, as it undermines wallet security without user error. The 129 million ADA containment figure highlights what was protected, but users who lost funds naturally focus on recovery. The bounty offer incentivizes the attacker to return assets, though success is not guaranteed. Attribution of the attack should remain cautious, as behavioral similarities do not prove identity. For the Cardano ecosystem, this incident underscores that DeFi security relies on application-layer controls, not just chain-level reliability. The renewed bounty keeps the door open for returned funds, but the situation remains unresolved until formal recovery is completed.

Source: https://bitcoinist.com/secondfi-renews-bounty-push-after-16-1m-cardano-exploit/