Crypto Prices

SecondFi Issues Urgent Advisory Against Claiming Vulnerable NIGHT Tokens

1 hour ago
2 mins read
1 views

Critical Alert for SecondFi Users

SecondFi has issued a critical alert for users whose wallets have been compromised, specifically advising against redeeming upcoming NIGHT token allocations. The security update comes after it was confirmed that tokens must be claimed from the original wallet addresses, which remain vulnerable following a security breach earlier this year.

Details of the Security Incident

On September 22, some users affected by a security incident that occurred between June 21 and June 23 of this year were scheduled to claim their NIGHT tokens. However, due to the fact that the associated wallets are permanently compromised, SecondFi has emphasized the risks of proceeding with claims. The company reached out to the Midnight Foundation to explore potential alternatives for claiming these tokens but found that the current redemption settings do not allow for transfers to a different wallet before claims are processed. Anyone holding NIGHT allocations linked to compromised SecondFi addresses is therefore at risk of theft if they choose to redeem their tokens now.

Guidance from SecondFi

In its guidance, SecondFi made it clear that the claim process is governed independently by the Midnight Foundation, separate from SecondFi’s operations, and that the company itself lacks any control over the claiming system. As such, users seeking assistance should consult the Midnight Foundation directly. SecondFi’s own recovery tools cannot address this specific claim issue, as their Wallet Migration Tool is tailored for transferring eligible assets from SecondFi wallets, and their Asset Recovery Tool is meant for assets compromised in the June incident. Neither tool has the capability to facilitate the claiming of NIGHT tokens.

Previous Communications and Vulnerability

This warning builds upon previous communications from SecondFi concerning the recovery process, indicating that there can be no assurance that NIGHT tokens redeemed to compromised wallets will remain secure. Although they aim to help affected users regain access to their Glacier Drop allocations, the nature of the vulnerability complicates the recovery process. In March, the Midnight network launched its privacy-centric mainnet, utilizing zero-knowledge proofs, with the NIGHT token distributed to eligible users through the Glacier Drop program.

Investigation Findings

As previously reported, an independent investigation by EMURGO revealed that over 16.1 million ADA, worth approximately $2.6 million, was stolen across 374 wallets due to a cryptographic vulnerability in SecondFi’s wallet software. This flaw allowed an attacker to derive valuable private key materials using publicly available transaction data, leading to the leak tied specifically to compromised wallets. Although SecondFi has since patched this flaw, wallets created with the updated software are not expected to be vulnerable.

Further investigations by Groom Lake, a blockchain intelligence firm engaged in the inquiry, identified signs of two distinct attacker groups. The primary incident appeared externally sophisticated and possibly linked to DPRK-related activities. As a precaution, SecondFi took remedial measures, shifting about 129 million ADA to third-party custodians while developing a secure wallet migration path for users. Their Wallet Migration Tool now facilitates the transfer of eligible assets to newly created wallets elsewhere on the Cardano network.

Future Recovery and User Precautions

While work continues to create a recovery portal for users to formally claim affected assets using zero-knowledge proofs, the claiming of NIGHT tokens operates outside this recovery framework. Thus, users facing the prospect of unclaimed allocations must choose between risking their credentials or forgoing their claims altogether.

Given these circumstances, users are strongly discouraged from deleting the SecondFi app and are reminded to retain their wallet seed phrases, as either might be vital for future recovery needs. Users have also been warned about scams claiming to offer recovery services and advised that SecondFi will never ask for private keys or recovery phrases.

As the situation develops, SecondFi continues to focus its operations on assisting affected users while urging them to direct questions about alternate claiming methods to the Midnight Foundation.

Popular