MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / DeFi / SecondFi Opens Recovery Portal After $21M Hack, Offers Victims 30 ADA Per Lost NFT
DeFi

SecondFi Opens Recovery Portal After $21M Hack, Offers Victims 30 ADA Per Lost NFT

By MABOnChain Desk · Published · Updated · 4 min read

Editorial digital-art illustration of a stern claims clerk behind a brass Recovery Claims counter handing a stack of blue Cardano ADA coins to an outstretched hand, while a locked vault cabinet labeled Unrecoverable displays framed colorful NFT artworks behind glass

Published October 8, 2026, 16:15 UTC. Reporting via SecondFi's recovery guide (as reported by NS3.AI on Binance Square), The Currency Analytics, Protos, the Crypto Times and U.Today.

SecondFi, the Cardano wallet firm behind a June 2026 hack that drained roughly $21 million across four separate wallet-draining events, has opened a recovery portal for victims, but holders of stolen NFTs that cannot be returned will get a flat 30 ADA per NFT, worth about $7.60 at current prices, according to The Currency Analytics, which reported the portal's launch on October 8.

The 30 ADA rule

Victims seeking recovery will be assessed against what SecondFi calls an "incident snapshot," a frozen record of holdings taken at the time of the June 2026 exploit. The company warns the snapshot is only an estimate and that, in its own words, "the final amount may differ." Any NFT that for some reason cannot be returned earns a fixed 30 ADA, which Protos valued at $7 and 60 cents. SecondFi's own FAQ, cited by the Crypto Times, frames the 30 ADA payment as a goodwill gesture rather than a valuation of the NFT. Victims must also claim through a newly created Cardano wallet, since recovered funds will not go back into the compromised addresses.

The recovery-phrase warning

The claims process comes with a red flag. An October 7 report by NS3.AI, published on Binance Square, says SecondFi's official recovery guide tells users to enter the private recovery phrase of their exploited wallet into SecondFi's webpage, a step that exposes users to serious security risk. That instruction sits awkwardly beside the company's earlier plan, developed with Input Output Group and the Cardano Foundation, for a zero-knowledge-proof refund portal that would let victims prove ownership without revealing seed phrases or private keys, as U.Today reported in July.

The security picture around the company remains unsettled. The Crypto Times reported in September that SecondFi's FAQ refers to four distinct wallet-draining events in total, and that emergency measures during the exploit secured about 129 million ADA, routed to an independent third-party custodian and held for the affected addresses. A wallet migration tool, already live, underwent an independent security assessment by Bitdefender, according to the same report. The company has said it will cease operations while it runs the recovery process.

The June hack

The original June exploit stole 16.1 million ADA, worth about $2.5 million at the time, from 374 SecondFi wallets by exploiting a vulnerability in the Android version of the app, U.Today reported, attributing the attack to the Lazarus Group. The hackers were able to cryptographically derive users' private keys, according to that report. Three months on, victims are only now getting a working claims portal, after the company twice pushed its recovery roadmap back from early-September targets.

This article is news reporting and is not investment advice.

Sources

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading

Regulation

U.S. Government Moves $770M in Seized Bitcoin to Coinbase Prime, Including $200M From Unknown Holdings

October 8, 2026 · 4 min read

Galaxy Research's October 7 on-chain analysis shows U.S. government-linked wallets sent 9,261 BTC worth about $770 million to Coinbase Prime across October 6 and 7. Nearly half came from funds recovered from the 2016 Bitfinex hack and another portion from known Binance seizures, but 2,456 BTC worth roughly $204 million arrived from wallets never before attributed to the government, which Galaxy said may represent new law enforcement seizures. The transfers do not confirm a sale, and no DOJ or Marshals statement has confirmed a new seizure.

DeFi

79thVault Loses $12.5M as Compromised Operator Key Drains 79AU Liquidity Pool

October 8, 2026 · 4 min read

A wallet holding the OPERATOR_ROLE on 79thVault's 79AU token contract moved 2.01 million tokens out of the project's main PancakeSwap liquidity pool on October 7, sold them back into the same pool across about 95 swaps, and walked away with 16,249 BNB worth roughly $12.5 million. Security monitors call it a suspected private key compromise or insider action; 79thVault has only posted a vague 'system upgrade' notice.

Markets

Evernorth Pushes XRPN Nasdaq Debut to October 12 After Administrative Delay

October 8, 2026 · 4 min read

Evernorth Holdings disclosed in an October 6 SEC filing that an administrative delay moved its merger with Armada Acquisition Corp. II to on or about October 9, with Class A shares beginning Nasdaq trading under ticker XRPN on or about October 12. The XRP treasury company still expects to hold about 473 million XRP at closing.

Markets

NEAR Climbs Into Crypto's Top 20 After 140% Monthly Surge

October 8, 2026 · 4 min read

NEAR entered the top 20 cryptocurrencies by market capitalization on Thursday with a $7.2 billion valuation after a 138% monthly rally, per CoinGecko. NEAR Intents has handled more than $31 billion in cumulative volume, Bitwise launched the first U.S. spot NEAR fund on September 29, and the Quantus Network launched the first post-quantum asset on the NEAR platform. NEAR Intents also recovered from a $3.8 million exploit last week, with all funds returned on October 2.