16.1M ADA Stolen, Lazarus Group Suspected: SecondFi Gives Hacker One Last Chance

The hacker who drained 16.1 million Cardano from DeFi lending protocol SecondFi may have ties to North Korea's Lazarus Group — and SecondFi just issued what it calls a final ultimatum to return the funds.

The breach happened in June. Months later, the stolen ADA remains unrecovered, a bounty is still on the table, and the emerging Lazarus link is turning this from a routine DeFi exploit into something far more serious.

What Happened

SecondFi, a Cardano-based lending protocol, was hit in June by an exploit that siphoned 16.1 million ADA from the platform. The team moved quickly to identify the attacker and has kept a recovery bounty active since the breach, offering the hacker a financial incentive to return the funds and walk away.

That offer is still open. But the window is closing.

In a public statement, SecondFi urged the hacker to return the stolen assets, framing it as a last chance before the team escalates to full legal and law enforcement channels. The ultimatum signals that internal investigations have likely reached a point where the team believes they have enough information to pursue the attacker, with or without cooperation.

The Lazarus Connection

The detail that should concern every ADA holder is the reported link to North Korea's Lazarus Group, the state-sponsored hacking collective responsible for over $3 billion in crypto theft since 2017 according to blockchain intelligence firms.

Lazarus doesn't return funds. They launder them through mixers, cross-chain bridges, and OTC desks, often across months or years. If the Lazarus connection holds, SecondFi's bounty offer may be more symbolic than practical — a paper trail for legal proceedings rather than a genuine recovery path.

The group has previously targeted DeFi protocols, centralized exchanges, and crypto bridges. Cardano, historically seen as a lower-profile target compared to Ethereum or Solana ecosystems, may now be firmly on their radar.

What This Means for ADA Holders

This story has two layers worth watching closely.

First, the immediate: 16.1 million ADA is sitting somewhere, potentially being slowly moved or liquidated. Large, coordinated sell pressure from laundered funds can create short-term price suppression, and ADA traders should monitor on-chain flow data for unusual wallet activity.

Second, the structural: a confirmed Lazarus attack on a Cardano DeFi protocol would mark a significant escalation in threat level for the ecosystem. Protocols building on Cardano, and users depositing into them, should treat this as a security benchmark moment.

Watch the SecondFi deadline closely. If no funds are returned and law enforcement steps in formally, the on-chain trail becomes evidence, and any wallet touching that ADA becomes a liability.