SecondFi says its reimbursement plan is now in the build phase after the June exploit, with 16 million ADA set to be returned to affected users. The platform said the stolen funds were worth about $2.4 million and were tied to 374 addresses. At the same time, it warned that some users are receiving malicious emails carrying links and fake recovery claims.
The flaw was in SecondFi software, not the Cardano chain
The exploit took place between June 21 and June 23. According to the update, attackers found a weakness in SecondFi’s wallet-generation software rather than in the Cardano blockchain itself. Cardano continued operating normally throughout the incident window.
The issue was tied to how the signer generated nonces during transaction signing. Once an affected address signed a transaction, attackers could reconstruct the private key using only public blockchain data. No direct seed phrase leak was required. That also means moving funds to a new wallet does not remove the exposure already attached to the compromised address.
Recovery work will unfold in two stages
EMURGO said forensic work has been completed and that the team has created a final balance snapshot for every affected account. That snapshot will serve as the basis for the claims process. Engineers are testing several technical options in parallel before any user funds are touched.
The timetable described by the team splits recovery into two weeks. The first week is for building the system, and the second is for testing and security checks. A wallet checker tool is expected early next week. After that, users will be given a separate process to move remaining assets out safely. The company stressed that neither step has started yet.
Users are told to wait and avoid unofficial instructions
SecondFi said no user action is required at this stage. Affected wallets should remain untouched until official instructions are published through the project’s real channels. The company also said it will never ask for a private key, seed phrase, wallet login details, or a transfer of funds. Any request of that kind should be treated as a scam.
It also advised users not to deposit new funds into existing SecondFi wallets for now, saying fake accounts have been copying its messaging. For support related to the incident, the only recognized ticket channel is support.secondfi.io.
The next checkpoint is the wallet checker launch
The report noted that EMURGO built its name around Yoroi before the SecondFi rebrand, which puts extra focus on how the reimbursement effort is carried out. The two-week target is tight for a case this sensitive, but the company says it is prioritizing testing and security checks over speed. The next concrete signal will come when the wallet checker tool goes live early next week.

