{"id":31147,"date":"2026-07-30T17:12:18","date_gmt":"2026-07-30T16:12:18","guid":{"rendered":"https:\/\/investx.fr\/en\/2026\/07\/30\/secondfi-exploit-16-million-ada-stolen-ultimatum-hacker\/"},"modified":"2026-07-30T17:12:24","modified_gmt":"2026-07-30T16:12:24","slug":"secondfi-exploit-16-million-ada-stolen-ultimatum-hacker","status":"publish","type":"post","link":"https:\/\/investx.fr\/en\/crypto-news\/secondfi-exploit-16-million-ada-stolen-ultimatum-hacker\/","title":{"rendered":"SecondFi Exploit: 16.1 Million ADA Stolen and an Ultimatum Issued to the Hacker"},"content":{"rendered":"\n

A DeFi<\/strong> protocol built on Cardano<\/strong> has just laid its cards on the table against the perpetrator of a massive ADA<\/strong> token theft. SecondFi<\/strong>, the victim of an attack last June, has issued a public ultimatum to the hacker while keeping a bug bounty offer on the table. Behind this case, a deeply troubling lead points toward one of the most feared cybercriminal groups in the world.<\/p>\n\n\n\n

SecondFi Under Pressure: 16.1 Million ADA Missing Since June<\/h2>\n\n\n\n

In June 2025, SecondFi<\/strong> \u2014 a decentralized lending<\/strong> protocol operating on the Cardano<\/strong> blockchain \u2014 fell victim to an exploit that allowed an attacker to drain 16.1 million ADA<\/strong>, a sum estimated at several million dollars based on prices at the time of the attack. The precise attack vector has not been fully disclosed publicly, a common practice to avoid providing a reusable blueprint for future exploits.<\/p>\n\n\n\n

Several weeks after the incident, the SecondFi<\/strong> team published an on-chain message and a statement across its official channels, addressed directly to the hacker. The protocol is granting a final deadline to return the stolen funds in exchange for a bug bounty<\/strong> \u2014 a now well-established practice in the DeFi<\/strong> ecosystem for attempting to recover assets without immediate legal action. Should the hacker cooperate, they would be allowed to keep a portion of the funds as a legitimate reward.<\/p>\n\n\n\n

This type of public ultimatum is a high-pressure negotiation strategy: by making the case visible, SecondFi<\/strong> increases the risk that the hacker’s wallets will be identified and blacklisted by centralized exchanges<\/strong>, making it far more difficult to convert the stolen ADA<\/strong> into fiat currency.<\/p>\n\n\n\n

The Lazarus Lead: When DeFi Meets State-Sponsored Cybercrime<\/h2>\n\n\n\n

The most alarming element of this case is the emergence of potential links to the Lazarus Group<\/strong>, the North Korean hacker unit tied to Pyongyang’s Reconnaissance General Bureau<\/strong>. This group is notably responsible for the $1.5 billion theft from Bybit<\/strong> in February 2025, one of the largest hacks in crypto history.<\/p>\n\n\n\n

If these links were to be confirmed, the probability of recovering the funds would collapse dramatically. Lazarus<\/strong> operates with sophisticated on-chain laundering<\/strong> techniques \u2014 mixers, cross-chain bridges, intermediary wallets \u2014 making tracing extremely complex, even for specialized firms such as Chainalysis<\/strong> or Elliptic<\/strong>. US and South Korean authorities have issued sanctions against several addresses associated with the group, but stolen funds are rarely recovered.<\/p>\n\n\n\n

For the Cardano<\/strong> ecosystem, this incident raises legitimate questions about the security maturity of DeFi<\/strong> protocols built on the blockchain. Cardano<\/strong> stands out for its eUTxO<\/strong> model and its Plutus<\/strong> smart contract language, both considered more secure than the EVM<\/strong>, but no architecture is immune to logical vulnerabilities at the smart contract<\/strong> or interface level.<\/p>\n\n\n\n

What Impact for Cardano and DeFi on ADA?<\/h2>\n\n\n\n
\"Cardano<\/figure>\n\n\n\n

Beyond the SecondFi<\/strong> case, this exploit comes at a time when Cardano<\/strong>‘s DeFi<\/strong> ecosystem is trying to establish itself against competitors such as Ethereum<\/strong>, Solana<\/strong>, and Avalanche<\/strong>. Protocols like Minswap<\/strong>, Liqwid<\/strong>, and WingRiders<\/strong> have gradually attracted liquidity, but the TVL (Total Value Locked)<\/strong> on Cardano<\/strong> remains modest compared to the sector’s leading chains. A hack of this scale can erode user confidence and slow the inflow of capital.<\/p>\n\n\n\n

On the price action side, ADA<\/strong> has not recorded any sharp move directly attributable to this incident \u2014 a sign that the market has not yet fully priced in the implications of this case, or that the relative size of the exploit is simply not large enough to weigh on Cardano<\/strong>‘s overall market cap. Key support levels remain closely watched by traders, particularly in a broader context of market-wide uncertainty.<\/p>\n\n\n\n

SecondFi<\/strong> has indicated that a full post-mortem analysis will be published once the situation is resolved. In the meantime, the ultimatum remains open \u2014 and the hacker, silent.<\/p>\n\n\n\n

\n\n\n\n

Related articles :<\/h3>\n\n\n\n