📈 Get daily crypto insights that make you smarter about your money

Do Not Claim Your NIGHT Tokens: Why SecondFi Is Telling Hack Victims to Walk Away From Tomorrows Midnight Redemption

Do Not Claim Your NIGHT Tokens: Why SecondFi Is Telling Hack Victims to Walk Away From Tomorrow’s Midnight Redemption

Cardano ecosystem wallet platform SecondFi has issued an urgent warning to users hit by its June security incident: do not claim your upcoming NIGHT token allocations, because Midnight’s redemption system only pays out through the original — and still compromised — wallet address.

Some users affected by the June incident are scheduled to claim NIGHT tokens on Sept. 22 under Midnight’s Glacier Drop distribution schedule. But the wallets tied to those allocations remain permanently compromised, and SecondFi says it has no way to protect the tokens once they land in an exposed address.

The problem, according to SecondFi, is structural. Midnight’s claim system requires NIGHT allocations to be redeemed through the original wallet and does not support moving an allocation to a different address before it is claimed. SecondFi said it contacted the Midnight Foundation to explore alternative claiming options before issuing the warning, but no workaround exists so far.

SecondFi’s guidance effectively tells holders that the only options are leaving the NIGHT allocation unclaimed or redeeming it into a wallet whose private key may already be in an attacker’s hands — and the company explicitly advises against the latter.

Why the wallets can never be safe again

The warning traces back to the SecondFi wallet security incident that unfolded between June 21 and June 23. An independent investigation commissioned by EMURGO found that approximately 16.1 million ADA, valued at roughly 2.6 million USD at the time, was stolen from 374 wallets.

SecondFi traced the root cause to a cryptographic flaw in how its wallet software generated signatures for individual transactions. A value that should have depended on secret information could, under certain conditions, be calculated using publicly available transaction data already recorded on the Cardano blockchain.

That distinction matters. Unlike a temporary application bug that can be patched and forgotten, the exposure remains permanently tied to the affected addresses and their private keys. Anyone holding the public blockchain data could, in theory, derive the private key material for those addresses. SecondFi has patched the flaw, and wallets created with the corrected software are not known to be vulnerable — but the old addresses can never be considered safe again.

Forensic investigators hired by EMURGO, blockchain intelligence firm Groom Lake, reviewed code, code history and public blockchain records. The investigation found evidence of two separate attackers: a primary operation described as sophisticated, externally funded and showing indicators being assessed for possible overlap with the DPRK-linked Lazarus Group, plus a second party that targeted a separate group of wallets during the same window.

Recovery tools don’t cover NIGHT

Since the incident, SecondFi has split its response into two tracks. Its Wallet Migration Tool lets users move eligible ADA, Cardano native tokens and NFTs still sitting in SecondFi wallets to freshly created wallets with another provider. A separate recovery effort — built around a zero-knowledge-proof portal that lets users prove ownership of compromised wallets — covers assets affected by the June incident.

Neither tool can help with NIGHT. The allocation has not yet entered the compromised wallet, and the claiming rules are controlled entirely by the Midnight Foundation, not SecondFi. As an emergency measure during the incident, SecondFi moved roughly 129 million ADA to an independent third-party custodian, but that safeguard also does not extend to future token claims.

The NIGHT token itself belongs to Midnight, a privacy-focused network built on zero-knowledge technology that launched its mainnet in March. NIGHT was distributed to eligible users through the Glacier Drop program, with allocations unlocking under scheduled redemption periods — a design that has now collided with SecondFi’s compromised addresses.

A platform that will not reopen

The NIGHT warning lands on top of an already bleak situation for SecondFi users. EMURGO confirmed in July that the wallet platform would not resume normal operations, and all remaining work on the platform has been redirected toward migration, claims and asset recovery.

SecondFi has told users not to delete the app and to keep their seed phrases, since at least one of the two will be needed for the recovery process. Users who already deleted the application must retain their seed phrase to recover eligible assets.

The company has also cautioned the community against fake recovery services and impersonators, stressing that SecondFi will never ask for private keys, recovery phrases or wallet credentials, and that its official tools never require users to sign a transaction simply to check whether an address was affected.

For NIGHT holders staring at a redemption date, SecondFi’s advice is blunt: direct questions about a safer claiming method to the Midnight Foundation, because changes to the claim process remain outside SecondFi’s control. Until Midnight offers an alternative, the safest move for affected users may be to let the allocation sit unclaimed rather than hand freshly minted NIGHT to the hackers who never left.

16 thoughts on “Do Not Claim Your NIGHT Tokens: Why SecondFi Is Telling Hack Victims to Walk Away From Tomorrows Midnight Redemption”

  1. brutal situation. you wait months for the Glacier Drop and then claiming it hands the tokens straight to whoever still has your keys. there is no good move here

  2. The Midnight Foundation really shipped a redemption system with no option to change the destination address? That is a design flaw independent of the SecondFi hack.

    1. ^ this. even without the June incident people lose phones and seed phrases. forcing redemption to the original address was always gonna burn someone

  3. Groom Lake doing the forensics for EMURGO is at least a serious look into how the keys leaked. Still does not help the people staring at a Sept 22 claim window they cannot safely use.

    1. Groom Lake can name whoever leaked the keys and it changes nothing for claim day. the NIGHT is bound to a burned address either way

  4. imagine patching the wallet flaw but the old addresses are dead forever anyway. walk away from the NIGHT, its gone, buy back your sanity

  5. so midnight forces the NIGHT payout to the original wallet, meaning hacked users would claim straight into the attacker address. brutal design flaw, hope they patch the claim target before sept 22

    1. got the secondfi notice too. losing the whole allocation stings but claiming night into a drained wallet helps nobody but the hacker

    2. sept 22 is literally tomorrow, no way they rewrite the claim flow that fast. midnight will just mumble user responsibility and move on

      1. they dont need to rewrite the whole claim flow, just blacklist the burned addresses and handle those payouts manually. midnight doing neither is the actual choice here

      2. they dont need to rewrite the whole claim flow, just blacklist the burned addresses and handle those payouts manually. midnight doing neither is the actual choice here

  6. Allocations should be claimable to any verified address. Until Midnight fixes that structural issue, walking away from the Glacier Drop is the only sane call for SecondFi users.

    1. exactly, and the Glacier Drop was pitched as the airdrop that finally fixes airdrops. same single point of failure as every claim before it

  7. imagine watching your NIGHT allocation sit there while the only move is claiming into the wallet that already drained you once. secondfi is right, just walk away

  8. SecondFi telling people to skip the claim is correct but it should never have been their call to make. Midnight shipped the single-address redemption design

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$85,988.00+6.7%ETH$2,750.96+6.5%SOL$118.61+9.6%BNB$797.75+5.9%XRP$1.51+9.0%ADA$0.2437+9.8%DOGE$0.0946+11.1%DOT$1.18+7.6%AVAX$11.20+3.1%LINK$13.04+7.3%UNI$8.96+3.9%ATOM$1.80+6.0%LTC$62.70+9.8%ARB$0.2358+17.7%NEAR$4.15+12.5%FIL$0.9793+6.9%SUI$1.04+26.1%BTC$85,988.00+6.7%ETH$2,750.96+6.5%SOL$118.61+9.6%BNB$797.75+5.9%XRP$1.51+9.0%ADA$0.2437+9.8%DOGE$0.0946+11.1%DOT$1.18+7.6%AVAX$11.20+3.1%LINK$13.04+7.3%UNI$8.96+3.9%ATOM$1.80+6.0%LTC$62.70+9.8%ARB$0.2358+17.7%NEAR$4.15+12.5%FIL$0.9793+6.9%SUI$1.04+26.1%
Scroll to Top