SecondFi has issued an unusual warning to users affected by its June wallet-security breach: do not claim NIGHT tokens through the compromised wallet.
Some affected users become eligible to redeem NIGHT through Midnight’s Glacier Drop on September 22. The allocation is tied to the same wallet whose private-key security has already failed.
Background: June incident
SecondFi suffered a security incident between June 21 and June 23, 2026.
The company later said approximately:
- 16.1 million ADA was stolen;
- 374 wallets were affected.
The incident was attributed to a cryptographic flaw in the transaction-signing process that could allow private-key recovery from public transaction information under affected conditions.
Emergency recovery saved more ADA
SecondFi also said emergency measures secured approximately 129 million ADA during the active incident and routed those assets toward independent third-party custody for affected addresses.
The accounting distinction matters:
- 16.1M ADA = reported stolen;
- ~129M ADA = assets SecondFi says it secured.
Why NIGHT creates a new problem
NIGHT is the token of Midnight, a Cardano-linked privacy network.
Its Glacier Drop allocation system ties claims to the original eligible wallet address.
SecondFi says it contacted the Midnight Foundation seeking an alternative. According to the current warning, the system requires the original wallet and does not allow the allocation to be redirected to an unaffected address before redemption.
Why claiming is unsafe
If an attacker can reconstruct or still controls the private key to an affected address, any new asset received by that address can also be moved by the attacker.
Claiming NIGHT does not repair the wallet. It can create a fresh balance in a wallet the attacker still controls.
SecondFi therefore advises affected wallet holders not to redeem NIGHT through the compromised address while no safe alternative exists.
SecondFi cannot change the NIGHT mechanism
SecondFi says NIGHT claim rules and redemption mechanics are controlled by the Midnight Foundation, not by SecondFi.
Its wallet migration and recovery tools cannot override the NIGHT allocation rule.
Users seeking an alternative are directed to official Midnight channels.
Recovery portal remains incomplete
Reporting around the June incident said affected-asset return mechanisms and a recovery portal were being developed. September coverage still described the recovery process as incomplete.
Users therefore face an unusual requirement: preserve the app or recovery evidence needed for restitution, while not treating the compromised wallet as safe for receiving new assets.
NFT and reward boundaries
SecondFi’s incident FAQ reportedly distinguishes between categories such as stolen NFTs, already allocated staking rewards and other reward balances.
That highlights why recovery cannot be reduced to one ADA reimbursement number.
Phishing risk
Users waiting for SecondFi recovery and NIGHT alternatives are high-value phishing targets.
SecondFi says it will not ask for private keys or recovery phrases. Any “safe NIGHT migration” service should be treated as Community / Unverified unless explicitly verified by SecondFi and Midnight.
Entity boundary
The June cryptographic flaw was a SecondFi wallet/signing issue.
The current NIGHT limitation is a Midnight claim-design constraint.
This does not establish a Cardano network compromise, NIGHT token exploit or Midnight blockchain exploit.
Evidence Status
Project-Reported / Current Warning
Some affected users have NIGHT claims beginning September 22; original wallet required; redirect unavailable; affected wallets permanently compromised; do-not-claim warning; SecondFi tools cannot override NIGHT.
Established June Incident Facts
Incident June 21–23; approximately 16.1M ADA stolen; 374 wallets affected; approximately 129M ADA reportedly secured.
Developing
Safe alternative claim path, Midnight response, recovery-portal completion, restitution timeline and NIGHT already lost from affected addresses.
Risk Assessment
High wallet / recovery-process risk.
The new risk does not increase the original ADA loss directly, but new assets can be stolen if users treat a permanently compromised address as safe.
What to Watch Next
Midnight claim-rule changes, alternative redemption, SecondFi recovery portal, custody/accounting of rescued ADA, additional NIGHT losses and phishing.
FAQ
Should affected SecondFi users claim NIGHT today?
SecondFi says they should not claim through compromised wallets under the current process.
Why can’t they use a new wallet?
Midnight’s current claim system reportedly ties the allocation to the original wallet.
How much ADA was stolen?
About 16.1 million ADA from 374 wallets.
What is the 129M ADA figure?
Assets SecondFi says emergency measures secured, not additional stolen value.
Is NIGHT itself hacked?
No such compromise is established.
Can a compromised seed become safe again?
No. A key an attacker can reconstruct/control should not be reused for fresh assets.