AdvertiseFee Deal Desk

Bitcoin

Second's Bitcoin (BTC) Ark System Drained of 0.75 BTC in Onboarding Exploit

Second lost 0.75 BTC, worth $62,322, to an exploit in its Ark onboarding flow. User funds sat in pre-signed exit paths and a patch shipped within hours.

Be a creator
October 8, 2026, 10:24 AM UTC4 min read
AI SummaryAI
  • Second lost 0.75 BTC worth $62,322 to an Ark server exploit on Monday.
  • The attacker registered transfer channels with a single signature and spent the same VTXO in parallel.
  • User funds stayed in pre-signed exit paths and were untouched, per the team.
  • Second disclosed a denial-of-service attack on Tuesday affecting Bark wallet Lightning receiving.
gate.com

0.75 BTC Siphoned From Second's Ark Server

Second, the team behind the Bark implementation of the Ark protocol, confirmed that an attacker drained 0.75 Bitcoin (BTC) from its own funds on Monday, a loss valued at $62,322 at the Bitcoin (BTC) price of that moment. The breach hit the Ark server onboarding flow, the step in which on-chain bitcoin moves onto Ark under signatures the server is supposed to co-sign. Onboarding is the most sensitive step in the Ark lifecycle, because that is where value crosses from direct chain custody into the protocol's shared-signature structure, and under that design every transfer into the layer-2 requires approval from both the user and the operator's server. In its incident post on X, the team confirmed the exploit and the shipped fix, describing how a flaw let the attacker register transfer channels with nothing but their own signature, sweep the funds inside those channels back to a wallet under their control, and spend the same VTXO from Second's node over the Lightning Network in parallel. VTXOs, virtual transaction outputs, are how Ark wallets represent Bitcoin (BTC), filling the role UTXOs play for coins held directly on the base chain. Customer balances came through untouched. The affected VTXOs already sat inside pre-signed exit paths, and the server held no ability to spend them, so the attacker never reached user money. The sum taken was company treasury, not customer deposits. Second put the outcome plainly: “The design did what it was supposed to, although we would have preferred to verify it a different way.” The intrusion was detected within hours, and a patch released the same day closed the registration flaw that had allowed one-sided channel setup.

Blink Wallet Trail and a Tuesday DoS Attack

The attacker's activity did not end with the patched hole. Second reported that the hacker attempted to route bitcoin connected to the Blink wallet security breach of September 19, a theft whose compromised coins had been circulating for roughly three weeks. That maneuver failed: the attacker had to fund the transaction board from an address under their own control and then send the funds back to that same address, ending the attempt without a gain. On Tuesday, the team disclosed a second pressure point, a denial-of-service attack against its infrastructure, and warned that it could reduce how efficiently Bark-based wallets receive payments over the Lightning Network. A denial-of-service vector does not move funds; it degrades service, which places it in a different category from the registration exploit. Bark is Second's implementation of Ark, a protocol built to settle Bitcoin (BTC) transfers off chain at high speed and low cost, part of the Bitcoin DeFi build-out that also includes teams such as Ark Labs working on their own versions of the design across the wider Bitcoin layer-2 ecosystem. Ark differs from custodial wrapped Bitcoin structures in that coins remain held as VTXOs with pre-signed exit routes back to the base chain rather than pooled in a bridge's custody, and the whole structure settles finally on Bitcoin's proof-of-work ledger. That property is what contained Monday's theft to company money, and it is also why the denial-of-service pressure, which degrades service rather than taking custody, is the residual risk the team is watching.

The arithmetic of the incident argues the design held: the attacker's parallel spend of a single VTXO across two routes created a provable on-chain record rather than a silent loss, and the 0.75 BTC figure is checkable against the transactions the team published in its post-mortem. The root cause, per Second's own account, was a registration step that accepted one signature where two were required; the patch restores the co-signing gate. What remains open is the denial-of-service pressure disclosed on Tuesday, described as a risk to Bark wallet receiving efficiency, with no update on whether it has stopped. As of the team's latest statement, the exploit itself is patched, user funds are intact, and the breach point is closed.

COINOTAG's editorial and research desk.

AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.