AdvertisementAdvertisementAdvertisementAdvertisement
Cryptocurrency

SecondFi Warns About NIGHT Tokens from Compromised Wallets

9/21/2026, 06:18 PM • Evgenia Sliv

(edited: 09/21/2026)

SecondFi Warns About NIGHT Tokens from Compromised Wallets

SecondFi warns owners of compromised wallets not to withdraw NIGHT tokens, allocations of which are scheduled for September 22. The reason is that the Midnight system requires tokens to be withdrawn through the original address and does not support any other. Wallets associated with these allocations remain permanently compromised, so the company advises not to touch them until the issue is resolved. SecondFi has contacted the Midnight Foundation, but the current redemption system does not allow for the transfer of the allocation until it is requested. SecondFi's migration and recovery tools do not cover the NIGHT requirement – the rules are set by the Midnight Foundation, and inquiries should be directed there.

The incident occurred from June 21 to 23: approximately 16.1 million ADA worth about $2.6 million were stolen from 374 wallets. An investigation commissioned by EMURGO revealed a cryptographic flaw in signature generation: a value that was supposed to depend on a secret was calculated from public data under certain conditions, allowing the private key to be extracted from the Cardano blockchain. Unlike a temporary vulnerability, the exposure remains tied to the address permanently. The defect has already been fixed. Forensic contractor Groom Lake found traces of two attackers; the main operation is described as complex and well-funded, with indicators of possible overlap with the Lazarus Group. After the attack, SecondFi transferred about 129 million ADA to an independent custodian.

Midnight launched its mainnet in March as a privacy-focused network based on zero-knowledge. The NIGHT token was distributed through Glacier Drop, and some SecondFi users received claims tied to compromised addresses. In July, EMURGO confirmed that the platform would not resume operations. SecondFi asks users not to delete the app and to keep their seed phrases, warns about fake recovery services, and reminds that it never asks for private keys or requires transaction signatures to verify an address.

Popular news