Community Trust ScoreVerified
Cardano wallet holders got a rough deal. SecondFi, the company at the center of a $21 million hack that hit in June 2026, opened a recovery portal offering victims roughly $8 per unrecoverable NFT — specifically 30 ADA, which works out to about $7.60 at current rates.
Why It Matters
The recovery efforts by SecondFi highlight the ongoing challenges faced by users in the crypto space regarding security and asset recovery following significant breaches. With the compensation offered being relatively low compared to the losses incurred, this situation underscores the importance of robust security protocols and the need for clearer recovery processes in the rapidly evolving NFT market. As the industry matures, such incidents could influence future investment decisions and trust in platforms handling digital assets.
Not exactly a windfall. For anyone who lost significant holdings in the breach, that figure probably stings. But it’s what SecondFi is putting on the table, and the company is asking affected users to go through a multi-step claims process just to get there. Victims need to check their exploited wallet addresses against what SecondFi calls an “incident snapshot” — basically a frozen record of holdings taken at the time of the hack. That snapshot is supposed to estimate what each victim lost, though SecondFi itself cautions the final compensation amount may vary from whatever the snapshot shows. So even the $7.60 figure isn’t fully guaranteed.
How the Recovery Portal Actually Works
The process isn’t quick. After verifying an affected wallet through the portal, the system generates a zero-knowledge proof — and that step alone can take up to 15 minutes. Once that’s done, the actual claims process can run up to five working days. Victims also need to set up a brand new Cardano wallet to receive any recovered assets, since the old wallets are considered compromised.
And here’s where it gets messy. SecondFi is asking users to enter their private recovery phrases directly on the company’s site. Security researchers and crypto veterans have screamed about this kind of practice for years — entering a seed phrase on any third-party website is a classic attack surface for spoofing and phishing. SecondFi’s own recovery portal carries that same risk, even if the company’s intentions are legitimate. Victims who are already burned by one breach now have to decide whether they trust the process enough to potentially expose themselves to another.
The portal itself launched late. SecondFi originally promised an August release. It didn’t happen. Multiple postponements followed before the portal finally went live. No specific explanation for the delays was given publicly.
What the Hack Actually Did
The June 2026 exploit came down to a “nonce derivation” issue. That’s a fairly technical vulnerability — essentially a flaw in how cryptographic keys were generated — that let attackers derive private keys from public information. Once hackers had those keys, the wallets were open. They took $2.4 million directly.
But the bigger number — $18.5 million — came from a white hat hacker. That person pulled the funds out as a protective move, trying to get the assets away from the attackers before more could be stolen. It’s a controversial tactic. Technically, moving someone else’s funds without permission is still unauthorized access, even if the intent is protective. Whether victims see that $18.5 million again depends entirely on what SecondFi can negotiate and recover. The total exposure from the incident adds up to $21 million when you combine both figures.
The nonce derivation flaw isn’t unique to Cardano, but it’s a serious one. Nonce reuse and derivation bugs have caused major losses across multiple blockchain ecosystems over the years. When a system generates predictable or recoverable nonces, private keys can sometimes be reverse-engineered — and that’s basically what happened here. It’s the kind of vulnerability that tends to sit undetected until someone actively looks for it, or until someone malicious finds it first.
SecondFi Winds Down, Emurgo Steps Back
SecondFi isn’t just running a recovery portal. The company is winding down its broader operations entirely to focus on getting stolen assets back. That’s a pretty dramatic pivot — basically shutting down normal business to deal with the fallout. It says something about how serious the breach was, and probably about how much pressure the company is under from affected users.
Emurgo, which co-founded Cardano and created SecondFi, pulled out of its Token2049 booth following the incident. Token2049 is one of the bigger crypto industry gatherings, so skipping it isn’t a small thing. The withdrawal was a public signal that the hack’s consequences were reaching well beyond SecondFi’s own balance sheet.
For the broader Cardano community, the incident raised uncomfortable questions. The ecosystem has worked hard to position itself as a more rigorously developed blockchain — one built on peer-reviewed research and formal methods. A nonce derivation vulnerability cutting through that reputation is painful. It doesn’t mean the whole platform is broken, but it does mean the security assumptions that users and developers rely on need a hard look.
The recovery portal is live now. Victims can submit claims. The zero-knowledge proof takes up to 15 minutes, the claims take up to five working days, and the payout for unrecoverable NFTs is 30 ADA — about $7.60. Whether that’s enough to rebuild trust with the Cardano community is a separate question entirely, and SecondFi hasn’t answered it yet.
Frequently Asked Questions
What is SecondFi offering victims for unrecoverable NFTs after the Cardano hack?
SecondFi is offering a fixed compensation of 30 ADA, equivalent to approximately $7.60, for each NFT that cannot be returned to its original owner.
What caused the $21 million Cardano wallet hack in June 2026?
The hack stemmed from a “nonce derivation” issue that allowed attackers to obtain private keys, resulting in $2.4 million stolen directly and an $18.5 million withdrawal by a white hat hacker as a protective measure.





