SecondFi has warned holders of compromised wallets not to redeem upcoming $NIGHT allocations after confirming that Midnight’s claim system requires tokens to be claimed through the original wallet address.
According to SecondFi, some users affected by its June security incident are scheduled to claim $NIGHT tokens on Sept. 22, but the wallets tied to those allocations remain permanently compromised. The company said it contacted the Midnight Foundation to explore alternative claiming options before issuing the warning.
An update for affected wallet holders with an upcoming $NIGHT claim
— SecondFi (@secondfiapp) September 21, 2026
Some affected wallet holders are scheduled to claim $NIGHT tokens tomorrow. We have been in touch with the Midnight Foundation regarding options for claiming; unfortunately, $NIGHT allocations can only be claimed…
Midnight’s current redemption system does not support moving an allocation to another wallet before it is claimed. $NIGHT tokens assigned to an affected SecondFi address must therefore be redeemed through that original address, which could expose the newly claimed assets to theft.
SecondFi urged affected users not to attempt the redemption while the issue remains unresolved.
SecondFi says $NIGHT claims cannot move to safe wallets
The restriction comes from the $NIGHT claim process operated by the Midnight Foundation, which manages the token’s redemption rules separately from SecondFi.
SecondFi said it has no control over the $NIGHT claiming mechanism and directed users seeking alternative options to the Midnight Foundation’s official channels.
The company’s own recovery tools cannot solve the problem. Its Wallet Migration Tool is designed to transfer eligible assets still held in SecondFi wallets, while a separate Asset Recovery Tool covers assets affected by the June incident.
Neither system can process or cover a $NIGHT claim.
The warning expands on guidance SecondFi has previously given affected users. Its incident FAQ says recovery of $NIGHT tokens redeemed to compromised wallets cannot be guaranteed because of the nature of the vulnerability. SecondFi said it was working to help affected users secure their Glacier Drop allocations and would publish verified updates through its official channels.
Midnight launched its mainnet in March as a privacy focused network using zero knowledge technology. Its $NIGHT token forms part of the network’s ecosystem and was distributed to eligible users through the Glacier Drop program.
The token distribution has involved allocations that become available under scheduled redemption periods, leaving some SecondFi users with $NIGHT claims tied to addresses later identified as compromised.
SecondFi wallet flaw exposed private key material
The problem stems from the SecondFi wallet security incident that occurred between June 21 and June 23.
An independent investigation commissioned by EMURGO found that approximately 16.1 million $ADA, valued at roughly $2.6 million, was stolen from 374 wallets during the incident.
SecondFi traced the root cause to a cryptographic flaw in the way its wallet software generated signatures for individual transactions. A value that should have depended on secret information could, under certain conditions, be calculated using publicly available transaction data.
The flaw could allow affected private key material to be derived from information recorded on the public Cardano blockchain. Unlike a temporary application vulnerability, the exposure remains tied to the affected address and private key.
SecondFi has since patched the flaw and said wallets created with the corrected software are not known to be vulnerable.
Groom Lake, an independent forensic investigation and blockchain intelligence provider engaged by EMURGO, reviewed code, code history and public blockchain records while investigating the breach.
Its investigation found evidence of two separate attackers. The primary operation was described as sophisticated, external and well funded, with indicators being assessed for possible overlap with known DPRK linked Lazarus Group activity. A second party appeared to have targeted a separate group of wallets during the same period, with no overlap between the affected addresses identified at the time.
Recovery tools cannot protect upcoming $NIGHT redemptions
Following the attack, SecondFi began separating its response into migration and recovery processes.
The wallet recovery plan initially involved engineers testing several methods to return assets safely. SecondFi moved approximately 129 million $ADA to an independent third party custodian as an emergency measure while work continued.
Its Wallet Migration Tool now lets users transfer eligible $ADA, Cardano native tokens and NFTs remaining in SecondFi wallets to newly created Cardano wallets with another provider. Non Cardano assets need to be moved through their respective network and wallet processes.
Affected users face a different procedure. SecondFi has been developing a recovery portal that uses zero knowledge proofs to allow users to prove ownership of compromised wallets and submit claims for assets affected by the June incident.
The $NIGHT redemption sits outside both processes because the allocation has not yet entered the compromised wallet and its claiming rules are controlled by Midnight.
SecondFi’s warning means users whose allocations are tied to affected addresses currently face a choice between leaving their $NIGHT allocation unclaimed or attempting to redeem it into an address whose private key may already be exposed.
The company has explicitly advised users to avoid the latter.
SecondFi is focused on asset recovery
SecondFi’s recovery work has become its main remaining operation since EMURGO confirmed in July that the wallet platform would not resume normal operations.
crypto.news previously reported that EMURGO instructed users to migrate from SecondFi even if their wallets were not identified as affected. Work on the platform was redirected toward migration, claims and recovering assets for users caught in the incident.
SecondFi has warned users not to delete its app and to retain their seed phrases because at least one of the two will be needed for the recovery process. Users who have already deleted the application need to retain their seed phrase to recover eligible assets.
The company has separately cautioned users against fake recovery services and impersonation attempts. SecondFi says it will never request private keys, recovery phrases or wallet credentials, while its official tools do not require users to sign transactions simply to check whether an address was affected.
For $NIGHT holders approaching their scheduled redemption, SecondFi said questions about a safe alternative claiming method should be directed to the Midnight Foundation because changes to the claim process remain outside SecondFi’s control.
cryptopolitan.com
cryptoslate.com
en.cryptonomist.ch