Published: July 29th, 2026
Cardano wallet provider SecondFi is shuttering operations after a software vulnerability allowed attackers to steal 16.1 million ADA, worth about $2.4 million, from 374 wallets. The breach is just the latest in a series of setbacks for the crypto industry's security record.
The company said it had patched the flaw and secured 129 million ADA before attackers could reach the funds. Even so, directors concluded that confidence in the platform could not be restored and confirmed it would not resume normal operations.
The incident follows a string of high-profile breaches that underscore how attackers are shifting attention away from blockchain protocols and towards the software, infrastructure and operational processes built around them.
SecondFi said the vulnerability allowed attackers to derive private key material from transaction data that was publicly visible on the Cardano blockchain. Once reconstructed, those keys gave attackers direct access to affected wallets without compromising the blockchain itself.
Cardano's consensus mechanism stayed intact throughout the incident. Blockchain intelligence firm Groom Lake, which investigated the breach, described the principal attacker as sophisticated and well funded.
Some indicators resemble activity previously associated with North Korea's Lazarus Group, although the firm said no formal attribution has been established. Investigators also identified a second, unrelated attacker targeting another group of wallets during the same period.
SecondFi plans to release wallet export tools in early August, followed later in the month by a zero knowledge recovery portal.
SecondFi's closure comes just days after decentralized lending protocol Bonzo suffered a separate exploit that resulted in losses of approximately $9.05 million.
Unlike the SecondFi breach, which centred on wallet security, Bonzo's losses stemmed from a flaw in price verification within a third-party Supra oracle contract on the Hedera network.
According to Bonzo's preliminary incident report, the attacker deposited 250 SAUCE tokens before submitting manipulated pricing data that dramatically inflated their value against HBAR. The artificial valuation allowed the account to borrow assets vastly exceeding the true value of its collateral.
The attacker ultimately withdrew 6.63 million USDC and 34.50 million wrapped HBAR. Based on the reference HBAR price used in the report, the withdrawals totalled roughly $9 million.
A second wallet borrowed about $1 million while the manipulated prices remained active. That wallet later contacted Bonzo through Discord, identified itself as a white hat participant and indicated it intended to return the funds. Bonzo therefore excluded those assets from its headline loss estimate, although it said total borrowing during the incident reached approximately $10.06 million before any recovery.
The repercussions were immediate. According to DefiLlama, Hedera's total value locked (TVL) fell nearly 40% within 24 hours to $25.7 million, while Bonzo's own TVL dropped by 77%.
Research from analyst firm Onchain Lens found the cryptocurrency industry lost roughly $1.3 billion from 224 publicly disclosed hacks in the first six months of 2026. Much of the damage came from a small number of large incidents.
The report suggests attackers are becoming less interested in discovering obscure coding flaws than in exploiting operational weaknesses surrounding digital assets. Compromised credentials, privileged access, phishing campaigns and oracle manipulation have become more productive than traditional smart contract exploits.
Access control failures accounted for the largest share of losses during the period. High profile incidents affecting Kelp DAO, Drift Protocol and Humanity Protocol together represented hundreds of millions of dollars in stolen assets after attackers obtained privileged access or critical credentials.
Phishing and social engineering accounted for a further $282 million in losses. Convincing employees or users to surrender sensitive information remains remarkably effective, particularly as security practices become more sophisticated elsewhere.
Oracle manipulation represented a smaller share of overall losses but continues to expose weaknesses wherever decentralised applications rely on external pricing information.
There's little sign that the pace of attacks will let up anytime soon. Over the past weekend (July 25th and 26th, 2026), two other cryptocurrency projects disclosed fresh security incidents. Neither matched the scale of SecondFi or Bonzo, yet both reinforced the steady rhythm of disclosures that has characterised 2026.
WEMIX reported that ownership of a contract connected to WEMIX$ had been compromised, resulting in the unauthorised issuance of approximately 5.23 million WEMIX$. Those assets were converted into WEMIX and USDC before moving across bridges to Ethereum and BNB Chain, where they were exchanged into assets including Ether and Tether.
The company said some of the proceeds reached centralised exchanges and that it had requested exchanges and stablecoin issuers freeze the attacker's wallets. Investigations remain ongoing, and the company cautioned that reported figures may change.
In a separate case, blockchain security firm Blockaid identified suspicious activity affecting Garden Finance. The incident resulted in approximately $450,000 worth of USDT being drained across Ethereum, Base, Arbitrum and BNB Chain before the application was taken offline.
Thailand's Securities and Exchange Commission filed a criminal complaint this week against cryptocurrency exchange Bitkub, and two former directors, over allegations that the company masked the scale of a 2021 cyberattack in regulatory reports.
The regulator alleges Bitkub failed to disclose the theft of digital assets worth approximately 1.7 billion baht, equivalent to around $47 million, in daily capital filings submitted between May and October 2021. According to local reports, the filings suggested the company's financial position remained largely unchanged despite the theft.
Bitkub disputes the allegations. The company said customers never suffered losses because its founders purchased replacement assets using their own funds before any shortfall became apparent. It added that the decision not to disclose the theft immediately reflected concerns about triggering panic withdrawals, and noted that regulators had subsequently confirmed customer holdings remained intact.
According to local media reports, former director Sakolkorn Sakavee has accepted personal responsibility for altering the filings without informing other executives, saying he feared public disclosure would provoke a run on the exchange. Police and prosecutors will now determine whether the case proceeds to court.