The company said transaction markers identified with Groom Lake resembled Lazarus Group methods as it rolled out a three-stage user compensation plan running into September 2026.
SecondFi renewed its public appeal to the hacker behind its June breach, saying its bounty offer still stands if the stolen funds are fully returned. The Cardano-focused wallet provider said a voluntary return would be the most direct way to resolve the case, but it is also moving ahead with a three-stage compensation program with the Cardano Foundation and Input Output Group after investigators found transaction markers that reportedly matched methods used by Lazarus Group. The attack took place between June 21 and June 23, 2026, when 374 wallets were compromised. Hackers stole 16.1 million ADA worth about $2.4 million to $2.6 million at the time. SecondFi said its technical team prevented a larger loss by securing another 129 million ADA that had been at risk and transferring those funds to an independent custodian. The compensation roadmap is now in progress. The current late-July phase covers collection, verification and processing of claims from affected users. In mid-August 2026, the company plans to release tools to let users securely export surviving assets to third-party platforms, with hardware wallets recommended. An automated compensation portal using zero-knowledge proofs (privacy-preserving cryptographic verification) is scheduled for early September 2026. The breach has also triggered a broader corporate retreat. EMURGO said it will fully wind down and liquidate the SecondFi and Yoroi brands, concluding that the project is no longer viable after the financial and reputational damage from the incident.