SecondFi warns compromised wallets should not claim Midnight NIGHT tokens

Daily Feed
SecondFi warns compromised wallets should not claim Midnight NIGHT tokens

SecondFi is warning users whose wallets were compromised in its June security incident not to claim upcoming NIGHT tokens, because Midnight’s redemption system reportedly requires the original wallet address, and that could put stolen-wallet users right back in the firing line.

  • Claims must come from the original wallet address.
  • Compromised wallets may be exposed again.
  • SecondFi says it cannot reroute NIGHT claims.
  • This is a design problem, not just a support issue.

SecondFi is a Cardano wallet platform that was hit by a security incident in June. Now it is telling affected users to hold off on redeeming NIGHT allocations tied to Midnight’s Glacier Drop program, because the claim process appears to be locked to the original wallet address. If that address is still unsafe, claiming the tokens could hand control right back to whoever still has access.

That is the ugly edge of crypto custody. A token claim can look harmless on paper and still turn into a trap if the wallet behind it has been exposed. The chain does not care that the owner was hacked. It just follows the rules.

According to SecondFi, the warning applies to users whose wallets were compromised in the June incident and who are scheduled for NIGHT claims on Sept. 22. SecondFi says Midnight’s current redemption system does not support moving an allocation to another wallet before it is claimed, and SecondFi’s own migration and recovery tools cannot process or protect NIGHT claims.

In plain English: if the claim has to happen through the same wallet that was already compromised, then the recovery path on one side and the claim logic on the other do not line up. That is not a small inconvenience. That is the difference between a safe claim and a second theft.

On blockchains like Cardano, control depends on private keys and signing authority. If an attacker can still sign for a wallet, they can usually move anything that lands there. So if NIGHT has to be claimed into an exposed address, users may be forced into a lousy choice: claim and risk losing the allocation again, or skip it and walk away from the tokens entirely.

SecondFi says it contacted the Midnight Foundation to explore alternatives before issuing the warning, but it also says it has no control over the NIGHT claiming mechanism and directed users to Midnight’s official channels for any other options. That is a polite way of saying the recovery team cannot patch over someone else’s claim rules.

The timing makes the problem more serious. Midnight launched its mainnet in March as a privacy-focused network using zero-knowledge technology. NIGHT was distributed through its Glacier Drop program. Zero-knowledge proofs can verify something without revealing the underlying secret, which is useful for privacy and eligibility checks. What they do not do, on their own, is solve a wallet that has already been compromised.

That is the core issue here. Privacy tech may be elegant. The claim design may be clean. But if redemption is hard-wired to the original address, users with exposed wallets are stuck with a system that assumes their keys are still safe. Sometimes they are. In this case, SecondFi says they are not.

The June incident was not minor. SecondFi said roughly 16.1 million ADA was stolen from 374 wallets, worth about $2.6 million at the time, during a period between June 21 and June 23. SecondFi also said it moved approximately 129 million ADA to an independent third-party custodian as an emergency safeguard.

EMURGO confirmed in July that SecondFi would not resume normal operations. EMURGO also commissioned an independent investigation by Groom Lake, which reviewed code, code history, and public blockchain records. Groom Lake found evidence of two separate attackers and described the primary operation as sophisticated, external, and well funded. It also said indicators were being assessed for possible overlap with activity linked to the Lazarus Group, the North Korea-linked hacking crew that keeps turning up in major crypto theft investigations.

That last point deserves restraint. “Being assessed for possible overlap” is not the same thing as a confirmed attribution. In crypto, people love to slap a big scary name on an incident before the evidence is fully nailed down. Good investigators do not work that way, and neither should readers.

SecondFi also says its official tools do not require users to sign transactions just to check whether an address was affected, and it warns users not to delete the app or throw away their seed phrases. A seed phrase is the recovery set of words that can restore a wallet, and it should be protected like the master key it is. Lose that, and you are not “forgetting your password.” You are losing the front door.

The bigger lesson is not hard to see. Token claims and airdrops often assume the original wallet is still usable. That works fine until a wallet is compromised. Then the system turns hostile to the very user it is supposed to serve. If a claim cannot be redirected before redemption, the design has already failed the recovery test.

For now, the practical takeaway is simple: users with compromised SecondFi wallets should not rush to claim NIGHT unless Midnight offers a safe alternate path through official channels. If no alternate path exists, the allocation may be effectively stranded. That is not adoption. That is paperwork with a security problem attached.

Key questions and takeaways

  • Why is SecondFi warning users not to claim NIGHT from compromised wallets?
    Because SecondFi says Midnight’s redemption system requires claims from the original wallet address, and an exposed wallet could let an attacker steal the allocation after it is claimed.

  • Can SecondFi move the NIGHT allocation to a new wallet?
    No. SecondFi says Midnight’s current system does not support moving an allocation before claim, and SecondFi’s recovery tools cannot process NIGHT claims.

  • What is the risk for affected users?
    They may have to choose between trying to claim and risking another theft, or avoiding the claim and potentially losing access to the tokens.

  • Does zero-knowledge technology solve this problem?
    Not by itself. Zero-knowledge proofs can help with privacy and eligibility checks, but they do not fix a claim system tied to a compromised wallet.

  • What does this say about crypto custody design?
    It shows that airdrops and token distributions need recovery-aware mechanics. If a wallet can be compromised, the claim flow should have a safe way to handle that before users are forced into a bad choice.

  • What should affected users do now?
    Follow official guidance only, keep seed phrases secure, and avoid using a compromised wallet unless Midnight provides a verified alternative claim method.

If Midnight does not offer a safe workaround, some users are left with a brutal little paradox: the tokens exist, the claim window opens, and the wallet they are tied to is exactly the one they can no longer trust. That is what bad recovery design looks like in crypto. The network keeps moving. The thief does too.

Further reading

A few useful references on Midnight, NIGHT claims, and the surrounding Cardano privacy push:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog