SecondFi Warns Users Against Claiming NIGHT Through Compromised Wallets
SecondFi has warned users that attempting to claim NIGHT tokens through compromised wallets may expose them to further attacks. The warning stems from a security incident in June, during which two attackers stole approximately 16.1 million ADA worth around $2.6 million at the time from 374 wallets.
The investigation into the breach found a cryptographic flaw in SecondFi's transaction-signing process that allowed sensitive private-key material to be derived from information available on the public Cardano blockchain. As a result, affected wallet keys could not be secured by updating the software, and the company subsequently patched the underlying vulnerability.
However, wallets already compromised remain permanently vulnerable, and SecondFi has advised users not to redeem NIGHT tokens through these addresses due to the risk of further attacks. The company is in touch with the Midnight Foundation regarding alternative claiming arrangements but notes that this process falls outside its control.