Second Says Ark Server Bug Drained 0.75 Bitcoin From Project
Second said no customer funds were affected and that it shipped a fix after identifying the attack within hours.

Second, the developer of the Bark implementation of the Ark Protocol, said a bug in its Ark server’s boarding flow let an attacker drain 0.75 Bitcoin (BTC) worth $62,322 from project funds.
The project said no customer funds were affected. Second said the attacker registered boards using only its own signatures, exited those boards to an external wallet and spent the same virtual transaction outputs, or VTXOs, from the project’s node through Lightning.
Boarding moves on-chain Bitcoin into Ark, a system designed to support faster, lower-cost off-chain payments. Ark represents off-chain balances as VTXOs, while pre-signed exit paths are intended to let users recover their funds without relying entirely on the server.
Second said customer VTXOs remained protected because the server could not spend those pre-signed exit paths. The team said it identified the attack within hours and shipped a fix.
Second also said attackers continued trying to exploit the system after the initial incident. The attempts caused a denial-of-service attack that could impair Lightning receives on wallets based on Bark.
The project said the attacker tried to use Bitcoin linked to the Sept. 19 Blink Wallet breach, but that attempt failed. The boards were instead funded from an address controlled by the attacker, Second said.
Second launched its Ark implementation on Bitcoin signet in March 2025. The project described Ark as a scaling protocol for fast, low-cost off-chain Bitcoin payments with self-custody.