- SecondFi warns affected users against claiming NIGHT through compromised wallets.
- Midnight currently requires NIGHT allocations to use their original wallet addresses.
- The June breach affected 374 wallets and resulted in 16.1 million ADA stolen.
SecondFi has warned affected users against claiming upcoming NIGHT allocations through compromised wallets. The restriction could expose newly claimed tokens to attackers, while SecondFi’s recovery tools cannot process NIGHT claims.
SecondFi Warns Users Against NIGHT Claims
Some affected SecondFi users are scheduled to claim NIGHT tokens on September 22. However, the allocations remain tied to wallet addresses compromised during the platform’s June security incident.
In a Sept. 21 post on X, SecondFi said it had contacted the Midnight Foundation to explore alternative claiming arrangements. However, Midnight’s current system only allows allocations to be claimed through their original wallet addresses.
Affected users therefore cannot redirect their NIGHT allocations to newly created, unaffected wallets. SecondFi advised users not to redeem the tokens through compromised addresses because any assets received could remain exposed to attackers.
The NIGHT claim process, including its rules and redemption mechanism, is controlled by the Midnight Foundation. SecondFi said the process falls outside its control.
SecondFi also clarified that its Wallet Migration Tool and Asset Recovery Tool cannot process or cover NIGHT claims. Users seeking potential alternatives have been directed to contact the Midnight Foundation through its official channels.
An update for affected wallet holders with an upcoming NIGHT claim
Some affected wallet holders are scheduled to claim NIGHT tokens tomorrow. We have been in touch with the Midnight Foundation regarding options for claiming; unfortunately, NIGHT allocations can only be claimed…
— SecondFi (@secondfiapp) September 21, 2026
June Security Incident Affected 374 Wallets
The warning stems from a security incident that occurred between June 21 and June 23. According to SecondFi, two attackers stole approximately 16.1 million ADA, worth about $2.6 million at the time, from 374 wallets.
An investigation commissioned by EMURGO identified a cryptographic flaw in SecondFi’s transaction-signing process. Under certain conditions, information available on the public Cardano blockchain could be used to derive sensitive private-key material.
The exposure meant that affected wallet keys could not simply be secured by updating the software. SecondFi subsequently patched the underlying vulnerability but said wallets already affected remained permanently compromised.
The investigation also identified two separate parties involved in wallet-draining activity. SecondFi said indicators linked to the primary operation were being assessed for possible connections to North Korea’s Lazarus Group, although no attribution has been confirmed.
Recovery Efforts Remain Separate From NIGHT Claims
SecondFi has continued working on recovery measures for users affected by the breach. The company has also developed tools allowing eligible assets to be migrated from unaffected wallets to new addresses.
For compromised wallets, however, the recovery process operates separately from Midnight’s NIGHT distribution system. SecondFi’s Incident FAQ states that recovery of NIGHT tokens redeemed to affected wallets cannot be guaranteed because of the underlying vulnerability.
As a result, the company has urged affected users to avoid claiming NIGHT through compromised addresses while alternative arrangements remain unresolved. It has also warned users about fraudulent recovery services and impersonation attempts.
SecondFi said legitimate support will not request private keys, seed phrases, or wallet credentials. However, users have been advised to rely only on links and updates published through SecondFi’s official channels.





Be the first to comment