BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

SecondFi Warns Users Not to Claim NIGHT From Hacked Wallets

Some SecondFi wallet holders who were affected by a security breach are due to claim NIGHT tokens tomorrow. SecondFi said the tokens can only be claimed from the original wallet, meaning user

AnonymousCryptoCompass newsroom
September 21, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

Some SecondFi wallet holders who were affected by a security breach are due to claim NIGHT tokens tomorrow. SecondFi said the tokens can only be claimed from the original wallet, meaning users cannot move the claim to a different, unaffected address.

SecondFi warned affected users not to claim the tokens through their compromised wallets because the NIGHT allocation could also be at risk. The company said it has discussed the issue with the Midnight Foundation, which controls the NIGHT claim process, but no alternative claim method is currently supported.

Users question SecondFi’s advice

The reaction from affected users shows how little room they feel they have to act. PW described the warning as “a huge hassle,” pointing to the basic problem: users are being told not to claim tokens they are entitled to because their wallets can no longer be trusted.

St focused on compensation. The user asked who would cover unauthorized NIGHT redemptions and the funds lost in the hack, and whether that responsibility falls on SecondFi or Midnight.

Ada questioned the lack of details from SecondFi, asking what Midnight actually said after the two sides discussed possible claiming options. Ada also suggested claiming the tokens and moving them immediately, while making clear that this was personal advice rather than an official solution.

Taken together, the comments show three different concerns: the inconvenience for affected users, uncertainty over who bears the financial loss, and frustration over the lack of a clear solution.

Does blockchain still see the same owner when a wallet is hacked?

SecondFi is shutting down its wallet service, but that does not erase the affected addresses from the Cardano network. The addresses still exist and can still receive tokens, but the person who controls the private key may no longer be the legitimate owner.

That distinction has caused problems before. In 2023, a compromised Ethereum wallet was still eligible for the Arbitrum airdrop. Recovery specialists built a system that bundled the funding, claim and transfer into one transaction so a bot watching the compromised wallet could not steal the tokens first. A similar recovery system was later built to rescue about $44,000 worth of unclaimed Gelato tokens from a compromised wallet.

The SecondFi case is harder because Midnight does not currently allow the receiving address to be changed. That means the usual solution, moving to a fresh wallet before claiming, does not work. It creates a gap between the address that qualifies for the tokens and the person who can safely control that address.

Midnight already had to pause NIGHT redemptions once

On June 28, Midnight temporarily stopped Glacier Drop redemptions after learning that some users were holding their allocations in affected SecondFi wallets. Midnight said the pause was a precaution and that its own infrastructure had not been compromised.

Redemptions resumed on July 9 after Midnight said it was satisfied that the redemption system itself was safe. But the SecondFi problem remained at the wallet level.

This also explains why the issue can keep returning even after SecondFi has stopped operating. SecondFi’s own migration guide says NIGHT redeemed to an affected wallet may be drained and may not be recoverable.  That is the more interesting story here: the security problem is no longer just about the assets stolen in June. It can continue to affect new assets that arrive months later.

DeFi Planet reported that SecondFi will shut down its SecondFi and Yoroi wallet services following a security breach that resulted in the theft of about 16.1 million ADA, worth roughly $2.6 million at the time. SecondFi had entered maintenance mode on June 23 after discovering a security vulnerability that affected a limited number of user wallets. The platform temporarily suspended its front-end services while it investigated the incident and worked to contain the threat. The investigation later led to the decision to wind down both wallet services.

 

Enjoyed this? BookmarkDeFi Planet, explore related topics, and follow us onTwitter,LinkedIn,Facebook,Instagram,Threads, and CoinMarketCap Community for seamless access to high-quality industry insights

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

The post SecondFi Warns Users Not to Claim NIGHT From Hacked Wallets appeared first on DeFi Planet.