SecondFi has released a fresh update on its Cardano wallet security incident, saying 374 wallets were affected across three separate attack events. The platform put confirmed losses at nearly 16 million ADA, or about $2.4 million, stressing that the figure reflects only what investigators have been able to verify directly.
The breach unfolded during a 72-hour period beginning June 22. In response, SecondFi moved the platform into maintenance mode while investigators worked through the attack path and containment measures. The company also referred to four separate wallet-draining events tied to the same incident, pointing to a broader pattern rather than a single isolated exploit.
Confirmed losses and funds secured in emergency action
Alongside the damage estimate, SecondFi said emergency rescue efforts helped secure about 129 million ADA before additional losses could spread. Those funds are now being held securely as the wider recovery process continues. Based on the company’s current disclosure, the key numbers are 374 affected wallets, three confirmed attack events, nearly 16 million ADA compromised, and roughly 129 million ADA secured.
The team said its loss count is based on forensic work and direct verification. That leaves room for later updates if ongoing investigation produces more confirmed findings.
Restoration fund set up for affected holders
SecondFi said it has established a dedicated, independently secured restoration fund to support reimbursement for every affected holder. According to the company, that fund will anchor a transparent claims process for users seeking recovery.
Reimbursement will take time. The platform said verification steps must be completed before any claim can move ahead, and it warned that accuracy will take priority over speed. SecondFi also said it has already mapped every wallet address affected in the exploit, which should support the next phase of claims handling and recovery work.
Normal operations remain paused pending outside review
SecondFi said it will not resume full operations until external security firms complete a full code-level review. A leading security firm, along with other independent partners, is examining the complete attack vector before normal access is restored.
The company also issued a clear warning to affected users: the compromise exists at the address and private-key level, so importing a seed phrase into another wallet app will not remove the underlying risk. Users have been told not to move funds on their own and not to migrate wallets independently until official recovery instructions are released.
SecondFi added that formal incident reports will be submitted to relevant authorities and that it intends to pursue available legal avenues to recover stolen assets and seek accountability.

