SecondFi has told users whose wallets were compromised in its June security breach not to claim the NIGHT tokens they are due to receive, because the only address those tokens can be sent to is the one attackers can still drain.
The warning leaves a group of hack victims with two options, neither of them good. They can leave their NIGHT allocations unclaimed or claim them into wallets whose private keys were exposed three months ago and cannot be repaired.
In a post on X at 06:40 UTC on September 21, 2026, SecondFi said some affected wallet holders were scheduled to claim NIGHT, the token of the Cardano-linked privacy blockchain Midnight, the following day.
The company said it had contacted the Midnight Foundation about alternatives, but that NIGHT allocations “can only be claimed from the original wallet,” and that claiming to a different, unaffected address is not supported by the foundation’s system.
A Claim Rule and a Broken Wallet
NIGHT is being distributed through Midnight’s Glacier Drop, which ties each allocation to a specific wallet address. Allocations unlock in stages rather than all at once, according to CoinDesk’s reporting on the distribution design, which is why some affected SecondFi users are only now reaching their claim window.
Under the rules SecondFi described, a holder must claim through the address the allocation is tied to. For most users that is routine. For SecondFi’s affected users, it is the problem. The company said the vulnerability leaves affected wallets “permanently compromised,” so any tokens that arrive in them are exposed to the same attackers. “For your security, please do not attempt to redeem your NIGHT allocation using an affected SecondFi wallet,” the company wrote.
SecondFi said the NIGHT claim process, its rules, and its redemption mechanism are managed entirely by the Midnight Foundation, a separate organization, and fall outside its control. Its own recovery tools, it said, cannot process or cover NIGHT claims. It directed users seeking alternative claiming options to contact the foundation through its official channels.
Some users have already learned the cost. SecondFi’s incident FAQ includes a question from users who redeemed NIGHT to an affected wallet and lost the tokens. The company’s answer is that it is working to help affected users secure the Glacier Drop, but that recovery of NIGHT redeemed to affected wallets “cannot be guaranteed given the nature of the vulnerability.”
How the Wallets Were Compromised
SecondFi, the EMURGO-built Cardano wallet previously known as Yoroi, was drained between June 21 and 23, 2026. According to the company’s incident FAQ, about 16.1 million ADA, worth roughly $2.6 million at the time, was taken from 374 wallets. EMURGO is one of the three organizations that founded the Cardano network.
The company said the root cause was a subtle flaw in how the wallet software generated signatures for each transaction. A value that should have been derived from secret information could, under certain conditions, be computed from public transaction data. In practice, that meant affected users’ private keys could be worked out from information anyone could read on the blockchain.
The damage sits at the level of the key itself, which is why it cannot be undone. A patch protects wallets created after the fix, but a private key that has already been exposed stays exposed. SecondFi said the flaw was also visible in a copy of the relevant code that had been published without authorization to a public GitHub repository, and that it is cooperating with authorities on the circumstances of that publication.
The company has stressed the limits of the incident. Not all Yoroi-generated wallets were affected, it said, and users who accessed hardware wallets through SecondFi or Yoroi were not compromised.
Two Attackers, One Under Assessment
EMURGO engaged Groom Lake, a blockchain forensics and intelligence firm, to investigate. According to the FAQ, Groom Lake reviewed code, code history, and public blockchain data and found that the main operation behind the transfers was sophisticated, external, and well-funded, with indicators consistent with a professional, state-aligned threat actor.
SecondFi said certain of those indicators are being assessed for potential overlap with activity linked to North Korea’s Lazarus Group. No attribution has been confirmed.
Groom Lake also identified a second party that appears to be separate from the main operation and that affected a different set of wallets during the same period. SecondFi’s FAQ refers to four distinct wallet-draining events in total.
What Recovery Looks Like
SecondFi has said it will cease operations. In the meantime it is running two separate processes.
The first is a wallet migration tool, already live, which lets users move transferable Cardano assets still sitting in unaffected SecondFi wallets to a new wallet with another provider. SecondFi said the tool underwent an independent security assessment by Bitdefender.
The second is a recovery portal for affected users, which the company said will let them prove ownership of their wallets using zero-knowledge proofs, a cryptographic method of proving something without revealing the underlying data. SecondFi said the portal is scheduled to launch in September 2026, and that launch dates may change if further security work is required.
The timeline has moved. In late June, EMURGO chief executive Phillip Pon said the company expected to begin returning assets within about two weeks. Nearly three months after the breach, SecondFi’s incident FAQ still describes the recovery portal as under development.
SecondFi also said in June that emergency measures taken during the exploit secured about 129 million ADA, which it said was being routed to an independent third-party custodian and held for the affected addresses.
The company has said its commitment is “unequivocal” to support the return of assets to affected holders across all four draining events. Its FAQ sets out the limits of that commitment. Stolen NFTs cannot be returned, so SecondFi said it intends to grant 30 ADA per eligible NFT confirmed lost as a goodwill gesture rather than a valuation. Staking rewards already allocated and transferred during the incident will be included in recovery; rewards not yet paid out will not. BRING cashback rewards on affected wallets cannot currently be collected safely, and SecondFi said it cannot confirm whether they will be recoverable.
Keep the App, Keep the Seed Phrase
SecondFi has told affected users not to delete the app or move their wallets. Either the app or the seed phrase will be required to claim recovered assets, the company said, and without one of them recovery will not be possible. Users who have already deleted the app were told to keep their seed phrase safe.
The company has also warned of fake SecondFi apps, browser extensions, and support accounts circulating since the breach. It said it will never ask for private keys or recovery phrases, never contact users first, and that its official wallet checker will never ask users to sign a transaction.
