Crypto.News SecondFi Alerts Users on Compromised Wallets for NIGHT Token Claims
Article Content
- •SecondFi warns users not to claim NIGHT tokens from compromised wallets.
- •Approximately 16.1 million ADA was stolen from 374 wallets in a June incident.
- •NIGHT token claims must be made from original compromised wallets, risking further theft.
SecondFi has issued a warning to users with compromised wallets not to redeem upcoming NIGHT token allocations, as the Midnight claim system mandates that tokens must be claimed from the original wallet address. Affected users, whose wallets were compromised in a June incident where approximately 16.1 million ADA was stolen, are scheduled to claim NIGHT tokens on September 22. SecondFi has confirmed that these wallets remain permanently compromised and has contacted the Midnight Foundation for alternative claiming options, which were not provided. The current redemption system does not allow moving allocations to safe wallets, exposing newly claimed assets to potential theft. SecondFi's recovery tools cannot assist with NIGHT claims, and the company has reiterated that recovery cannot be guaranteed. The incident highlights a flaw in SecondFi's wallet security that exposed private key material, leading to significant financial loss.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Lazarus Group and SecondFi in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…