According to Foresight News, SecondFi disclosed details of a second attack in a recent security incident update. A third-party attacker, unrelated to the initial hacker, exploited the same vulnerability approximately two weeks ago, stealing about 4 million ADA and multiple Cardano-native tokens from affected user wallets. SecondFi said the team contacted the attacker's wallet address on-chain and proposed a white-hat solution: return 90% of the stolen assets (approximately 3.618 million ADA and related tokens) to a designated recovery address and keep 10% (approximately 402,000 ADA) as a bounty, with a deadline of July 11, 2026, 7:59 AM.
The team stated the deadline has passed without a response from the attacker. SecondFi emphasized it has not waived the right to continue investigation, coordinate third parties, or pursue legal and law enforcement remedies, with future updates to be shared through official channels.