Home » SecondFi NIGHT Claim Warning Hits Users

SecondFi NIGHT Claim Warning Hits Users

by Ouess Crypto
A hand holding a dark hardware wallet displaying glowing text that reads "SecondFi NIGHT CLAIM WARNING: HITS USERS" in a dark setting.

SecondFi NIGHT claim warning has gone out to affected users. Specifically, SecondFi told holders of compromised wallets not to redeem upcoming NIGHT allocations.

The warning followed a confirmation from Midnight’s claim system. That system requires users to claim tokens through the original wallet address.

Why the SecondFi NIGHT claim warning matters

SecondFi said some affected users will claim NIGHT tokens on September 22. However, those wallets remain permanently compromised. SecondFi contacted the Midnight Foundation to explore alternatives. Then it issued the warning.

Midnight’s redemption system cannot move an allocation to another wallet. Therefore, affected users must redeem through the original address. That exposes newly claimed assets to theft. SecondFi urged users not to attempt redemption until resolved.

SecondFi NIGHT claim warning blocks safe redemptions

The restriction comes from the Midnight Foundation. It manages NIGHT redemption rules separately. SecondFi says it has no control over the claiming mechanism. Therefore, it directed users to Midnight’s official channels.

SecondFi’s recovery tools cannot solve the problem. Its Wallet Migration Tool transfers eligible assets in SecondFi wallets. Its Asset Recovery Tool covers assets from the June incident. Neither system can process a NIGHT claim.

The incident FAQ says recovery of NIGHT tokens cannot be guaranteed. SecondFi said it was working to help affected users. It will publish verified updates through official channels.

Midnight launched mainnet in March. It is a privacy-focused network using zero-knowledge technology. Its NIGHT token forms part of the ecosystem. The Glacier Drop program distributed tokens to eligible users. Allocations become available under scheduled redemption periods. Some SecondFi users now have NIGHT claims tied to compromised addresses.

SecondFi wallet flaw exposed private key material

The problem stems from the SecondFi wallet incident. It occurred between June 21 and June 23. An independent investigation by EMURGO found losses. Attackers stole approximately 16.1 million ADA from 374 wallets. The value was roughly $2.6 million.

SecondFi traced the root cause to a cryptographic flaw. Its wallet software generated signatures for individual transactions. A value should have depended on secret information. Under certain conditions, it could be calculated from public data. Therefore, private key material could be derived from Cardano’s public blockchain. This exposure remains tied to the address and private key. It is not a temporary app vulnerability.

SecondFi patched the flaw. It said it does not know of vulnerabilities in wallets created with corrected software.

Groom Lake reviewed code, code history, and public blockchain records. It found evidence of two separate attackers. The primary operation was sophisticated, external, and well funded. Indicators may overlap with Lazarus Group activity. A second party targeted a separate group of wallets. The two groups did not overlap at the time.

Recovery tools cannot protect upcoming NIGHT redemptions

After the attack, SecondFi split its response. It created migration and recovery processes. The wallet recovery plan involved testing several methods. SecondFi moved about 129 million ADA to an independent custodian. That was an emergency measure.

SecondFi designed its Wallet Migration Tool to transfer eligible ADA. Users can also move Cardano native tokens and NFTs. They move them to new wallets with another provider. Non-Cardano assets need separate network and wallet processes.

Affected users face a different procedure. SecondFi has been developing a recovery portal. It uses zero-knowledge proofs. Users can prove ownership of compromised wallets. Then they can submit claims for affected assets.

The NIGHT redemption sits outside both processes. The allocation has not entered the compromised wallet yet. Midnight controls its claiming rules. Therefore, SecondFi’s warning leaves users with a choice. They can leave NIGHT unclaimed. Or they can attempt redemption into an exposed address. SecondFi advised users to avoid the latter.

SecondFi is focused on asset recovery

SecondFi’s recovery work is now its main operation. EMURGO confirmed in July that the platform would not resume normal operations. It instructed users to migrate from SecondFi. This applied even if wallets were not identified as affected. Work shifted toward migration, claims, and asset recovery.

SecondFi warned users not to delete its app. It also told them to retain seed phrases. Users will need at least one for recovery. Users who deleted the app need their seed phrase. That helps recover eligible assets.

The company also cautioned against fake recovery services. It said it will never request private keys or seed phrases. Its official tools do not require transaction signing just to check an address.

For NIGHT holders, questions about safe alternatives go to Midnight Foundation. Changes to the claim process remain outside SecondFi’s control.

You may also like

Crypto Feed Logo Footer
Crypto Feed Logo

Crypto feed news

Our team of crypto enthusiasts and market mavens is on a mission to deliver the latest, juiciest, and most insightful updates from the ever-evolving world of cryptocurrencies.

@CryptoFeedNews 2023 All Right Reserved. Designed and Developed by TheDevThingz

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More

Privacy & Cookies Policy
Social Media Auto Publish Powered By : XYZScripts.com