Dear SingularityNET Community,
On September 19, an unauthorized party gained access to part of our cloud infrastructure and used it to mint tokens and withdraw assets through our bridge infrastructure. Treasury and exchange wallets were not affected, and FET held in your own wallet or on an exchange was not impacted. We revoked the compromised access and deactivated the affected bridges and conversion contracts, and our team and security partners responded as soon as the activity was detected.
Actions Taken:
- We revoked the identified compromised access
- Deactivated the bridges and conversion contracts
- Paused AGIX and NTX transfers on Ethereum
- Tracing and monitoring are ongoing, and we are working with exchanges and security partners
Current Status:
- FET: FET was withdrawn from the token converter. FET has been secured, and its minting controls were not affected. No action is required from token holders; your own wallets are not at risk from this incident.
- AGIX: Our team is working on a secure and compliant way for eligible holders to transfer their tokens, and we will share details as they are confirmed.
- NTX, WMTX, CGV: Unauthorized tokens were minted. We recognize the disruption this has caused these communities and their project teams, and we are in direct contact with each of them.
Next steps:
- Independent security review: We have been working closely with our security partners since the incident began. The bridges will stay deactivated until an independent security review confirms they are safe to restore, and we will share additional findings as they become available.
- AGIX holders: AGIX migration is paused. We are working on a legitimate, verified path forward for eligible holders, in a way that is legally sound, and we will share details as they are confirmed.
- Other affected tokens: We are working with each project team on next steps. Each team will communicate about its own token through its official channels.
- Exchanges and tracing: Monitoring continues, and we are sharing data with exchanges and partners who need it.
- Law enforcement: We are working with law enforcement in the relevant jurisdictions and will provide updates when available.
We are committed to working with every affected community and project team, and we will keep updating you as facts are confirmed. All updates will come only through our official channels. Do not trust information from any other source.
This was a coordinated, multi-stage attack with a high degree of automation. Our systems are audited regularly and we follow industry security standards, but attacks like this are accelerating and becoming more sophisticated. We encourage every team in this space to review their external cloud critical infrastructure now.
DRep notification:
- I voted YES on the proposal: Reduce minPoolCost to 75 ada.
Details for the decision are in the previous bundled proposal.
- I abstained on the proposal: Should stakePoolTargetNum (k) be raised from 500 to 1000? (SPO poll).
This info action is for SPOs.
Update on ADA Staking Rewards for Affected Wallets
We’ve received several questions about staking rewards following the recent security incident. Here is what you need to know:
Is my affected wallet still earning rewards?
No. The ADA in affected wallets is no longer staked, meaning these addresses are not actively earning new rewards.
Will lost rewards be compensated?
- Already-allocated rewards: If rewards were allocated and transferred to an affected wallet during the incident period, they will be included in the recovery process.
- Unallocated rewards: Rewards that were not yet allocated or paid out at the time of the incident are not currently included in the claim process.
📖 Read the full breakdown in our Incident FAQ: https://t.co/kJlmLeKfx3
⚠️ Stay safe:
Always verify links through our official channels only: @secondfiapp, @secondfi_jp, and https://t.co/bKfl8SK9D2.
Midnight Discord provides inaccurate guidance. They instructed me to use the same keys on another wallet and then claim NIGHT. However, the keys were hacked through Yoroi, meaning any wallet you use those keys with will be swept and drained of funds. SecondFi is supposedly developing a solution.
⚠️ @MidnightNtwrk smart contracts are coming to mainnet! 🚀
Why is this such a BIG deal?
▪️ With private smart contracts developers can start building applications with privacy from the start.
▪️ With private custom tokens you can mint tokens for payments, assets and apps while keeping sensitive transaction data private.
But this is only the beginning...
The next version of smart contracts is already on testnet, and will bring things like events and composability.
That could unlock:
🔓 Private DeFi
🔓 More private assets (like credits & invoices)
🔓 Applications that can combine multiple smart contracts
🔓 More flexible on-chain interactions
🔓 Real-world financial applications
Privacy is becoming programmable...
& Midnight is about to turn some heads! 👀🔥
An update for affected wallet holders with an upcoming NIGHT claim
Some affected wallet holders are scheduled to claim NIGHT tokens tomorrow. We have been in touch with the Midnight Foundation regarding options for claiming; unfortunately, NIGHT allocations can only be claimed from the original wallet. Claiming from a different, unaffected wallet address is not supported by their system.
Because the vulnerability leaves affected wallets permanently compromised, attempting to claim NIGHT to an affected address puts those tokens at risk. For your security, please do not attempt to redeem your NIGHT allocation using an affected SecondFi wallet.
Please note:
- NIGHT Claim Process: The NIGHT claim process, rules, and redemption mechanism are managed entirely by the Midnight Foundation, a separate organization, and fall outside of SecondFi's control.
- Scope of SecondFi Tools: While our Wallet Migration Tool and Asset Recovery Tool are designed to help you recover assets safely, they cannot process or cover the NIGHT claim.
If you have questions or wish to inquire about alternative safe claiming options, please contact the Midnight Foundation directly through their official channels.
For further details on asset recovery, please visit our Incident FAQ: https://t.co/kJlmLeKfx3
Safety reminder: Only rely on links published through our official channels (@secondfiapp and @secondfi_jp).
⚠️ A malicious app just read crypto wallets it was never supposed to touch.
It didn't fake anything.
It didn't trick anyone into entering their seed phrase.
It just exploited an iOS vulnerability and pulled the data directly from other apps on the same phone.
SlowMist and OKX confirmed it: FomoPepe versions 1.1-1.2 contained a kernel exploit that escapes the app sandbox and reads straight from your Keychain.
The wallet app was real. The user did nothing wrong. Didn't matter.
This is the problem with storing keys on a smartphone.
You're not just trusting your wallet app. You're trusting every other app on the device, every system vulnerability, and every future exploit nobody has found yet.
Updating iOS helps. But you're always one step behind.
There's only one way to stay ahead: never keep your keys on your phone.
🔐 A hardware wallet generates and stores your seed phrase offline. What's never in that environment can never be taken from it.
There are just 103 days until the EU's deforestation rules apply to importers of cocoa, coffee, and soy.
They'll need a supply chain record anyone can verify and no one can quietly rewrite.
That's where Cardano comes in: open, tamper-evident, built to last.