Crypto news report · source clearly identified
SecondFi warns users not to claim NIGHT tokens from compromised wallets
SecondFi has warned holders of compromised wallets not to redeem upcoming NIGHT allocations after confirming that Midnight’s claim system requires tokens to be claimed through the original wallet address.

SecondFi has issued a warning to users whose wallets were compromised in the June 2023 security incident. The warning advises against redeeming upcoming NIGHT token allocations through those affected addresses.
Why the warning matters
The Midnight Foundation’s claim system for NIGHT tokens can only process redemptions from the original wallet address that received the allocation. It does not support moving the claim to a different address before redemption. Because the private keys of the compromised wallets may be exposed, claiming NIGHT tokens from those wallets could result in the newly minted assets being stolen.
Scope of the issue
- Approximately 16.1 million ADA was stolen from 374 wallets during the June incident.
- Some of those wallets are scheduled to claim NIGHT tokens on September 22 as part of the Glacier Drop program.
- SecondFi’s migration and recovery tools cannot process or protect NIGHT claims.
SecondFi’s response
SecondFi has contacted the Midnight Foundation to explore alternative claiming options but acknowledges that the claim process is controlled by Midnight and outside SecondFi’s authority. The company’s Wallet Migration Tool can move eligible ADA, Cardano native tokens, and NFTs to new wallets, while a separate Asset Recovery Tool addresses assets already affected by the June breach. Neither tool covers NIGHT token claims.
What users should do
- Do not attempt to redeem NIGHT allocations from compromised wallets.
- Direct any questions about alternative claiming methods to the Midnight Foundation’s official channels.
- Retain seed phrases and avoid deleting the SecondFi app, as they may be needed for recovery processes.
Background on the June breach
An independent investigation commissioned by EMURGO identified a cryptographic flaw in SecondFi’s wallet software that allowed private key material to be derived from public blockchain data. The breach involved two separate attackers, with one group showing possible links to the Lazarus Group. SecondFi has patched the flaw and moved roughly 129 million ADA to a third‑party custodian as an emergency measure.
Source & attribution
News Source
- Publisher
- crypto.news
- Original date
- September 21, 2026, 9:43 AM
- Original headline
- SecondFi warns users not to claim NIGHT tokens from compromised wallets