Risk Radar

/ high

SecondFi NIGHT Claim Risk: Compromised Wallets Cannot Redirect Midnight Allocations

SecondFi says wallets compromised in its June Cardano signing-key incident should not claim NIGHT because Midnight currently requires redemption through the original wallet. The June breach affected 374 wallets and stole about 16.1M ADA.

September 22, 2026Last updated 10:30 UTC4 min read

SecondFi has issued an unusual warning to users affected by its June wallet-security breach: do not claim NIGHT tokens through the compromised wallet.

Some affected users become eligible to redeem NIGHT through Midnight’s Glacier Drop on September 22. The allocation is tied to the same wallet whose private-key security has already failed.

Background: June incident

SecondFi suffered a security incident between June 21 and June 23, 2026.

The company later said approximately:

  • 16.1 million ADA was stolen;
  • 374 wallets were affected.

The incident was attributed to a cryptographic flaw in the transaction-signing process that could allow private-key recovery from public transaction information under affected conditions.

Emergency recovery saved more ADA

SecondFi also said emergency measures secured approximately 129 million ADA during the active incident and routed those assets toward independent third-party custody for affected addresses.

The accounting distinction matters:

  • 16.1M ADA = reported stolen;
  • ~129M ADA = assets SecondFi says it secured.

Why NIGHT creates a new problem

NIGHT is the token of Midnight, a Cardano-linked privacy network.

Its Glacier Drop allocation system ties claims to the original eligible wallet address.

SecondFi says it contacted the Midnight Foundation seeking an alternative. According to the current warning, the system requires the original wallet and does not allow the allocation to be redirected to an unaffected address before redemption.

Why claiming is unsafe

If an attacker can reconstruct or still controls the private key to an affected address, any new asset received by that address can also be moved by the attacker.

Claiming NIGHT does not repair the wallet. It can create a fresh balance in a wallet the attacker still controls.

SecondFi therefore advises affected wallet holders not to redeem NIGHT through the compromised address while no safe alternative exists.

SecondFi cannot change the NIGHT mechanism

SecondFi says NIGHT claim rules and redemption mechanics are controlled by the Midnight Foundation, not by SecondFi.

Its wallet migration and recovery tools cannot override the NIGHT allocation rule.

Users seeking an alternative are directed to official Midnight channels.

Recovery portal remains incomplete

Reporting around the June incident said affected-asset return mechanisms and a recovery portal were being developed. September coverage still described the recovery process as incomplete.

Users therefore face an unusual requirement: preserve the app or recovery evidence needed for restitution, while not treating the compromised wallet as safe for receiving new assets.

NFT and reward boundaries

SecondFi’s incident FAQ reportedly distinguishes between categories such as stolen NFTs, already allocated staking rewards and other reward balances.

That highlights why recovery cannot be reduced to one ADA reimbursement number.

Phishing risk

Users waiting for SecondFi recovery and NIGHT alternatives are high-value phishing targets.

SecondFi says it will not ask for private keys or recovery phrases. Any “safe NIGHT migration” service should be treated as Community / Unverified unless explicitly verified by SecondFi and Midnight.

Entity boundary

The June cryptographic flaw was a SecondFi wallet/signing issue.

The current NIGHT limitation is a Midnight claim-design constraint.

This does not establish a Cardano network compromise, NIGHT token exploit or Midnight blockchain exploit.

Evidence Status

Project-Reported / Current Warning

Some affected users have NIGHT claims beginning September 22; original wallet required; redirect unavailable; affected wallets permanently compromised; do-not-claim warning; SecondFi tools cannot override NIGHT.

Established June Incident Facts

Incident June 21–23; approximately 16.1M ADA stolen; 374 wallets affected; approximately 129M ADA reportedly secured.

Developing

Safe alternative claim path, Midnight response, recovery-portal completion, restitution timeline and NIGHT already lost from affected addresses.

Risk Assessment

High wallet / recovery-process risk.

The new risk does not increase the original ADA loss directly, but new assets can be stolen if users treat a permanently compromised address as safe.

What to Watch Next

Midnight claim-rule changes, alternative redemption, SecondFi recovery portal, custody/accounting of rescued ADA, additional NIGHT losses and phishing.

FAQ

Should affected SecondFi users claim NIGHT today?

SecondFi says they should not claim through compromised wallets under the current process.

Why can’t they use a new wallet?

Midnight’s current claim system reportedly ties the allocation to the original wallet.

How much ADA was stolen?

About 16.1 million ADA from 374 wallets.

What is the 129M ADA figure?

Assets SecondFi says emergency measures secured, not additional stolen value.

Is NIGHT itself hacked?

No such compromise is established.

Can a compromised seed become safe again?

No. A key an attacker can reconstruct/control should not be reused for fresh assets.