Night token site offline

Hello guys,
Redeem site is offline has to do something with this secondFi exploit that stole ada from wallets i read.
Any idea how long we wait for online?
What is the action cardano is taking??
If it stays very long offline more then the thaw we are in any effect in the redeem time process?
Lets hope charles fix this fast​:face_with_peeking_eye:
Thanks

There is a Discord server in which they make these announcements; you can follow this link to sign up: https://discord.com/invite/midnightnetwork

Once getting access to the server you can see the announcement of paused redemptions on 28 June. There’s been no follow-up announcement that they’ve resumed, but assume it will also be in that server’s #announcements channel.

This announcement was also in their blog (Glacier Drop Redemptions Temporarily Suspended) and so we could also assume that resuming the redemptions would also be posted there.

It’s also worth repeating their very appropriate warning to watch out for fakes in the meantime & certainly not participate in any “alternative” redemption programme that’s located or working differently than the original or available before the official Midnight announcement that redemptions have resumed.

p.s. You can also ask your questions above on the Discord but I doubt you would hear any other response than “Please wait until the redemption portal is open again.”

2 Likes

Interesringly, attackers could probably still interact with the contracts directly. I would be very surprised if they had a kill-switch to pause them completely.

2 Likes

Hope charles and his briljant team is working hard and precise to get it straight and secure the loophole…..wich smartcontract are we talking about? Possible to cancel this one? Or put out of system???
Thanks hepta​:+1:

cough

There is not really something wrong with any smart contract. It’s more a suboptimal design decision.

When setting up the redemption system, they decided that you can never change the address that the NIGHT go to. They will always go to the address that they were originally assigned to.

That always was not so super smart considering addresses that become compromised at some point, but honestly, I also did not realise how not smart that was. Just thought that it is mainly a minor inconvenience for people who had their allocations distributed over lots of addresses or who would rather choose another account as destination in hindsight.

But since the SecondFi vulnerability (see https://adatool.net/secondfi-recovery?lang=en for a summary), we have a lot of compromised addresses where the private key can be very easily derived from on-chain data.

It would have always been a problem for the small number of people getting their seed phrase compromised through one or the other scam, but now it affects hundreds, maybe thousands of people who really did nothing wrong.

An attacker could quite easily claim the already thawed NIGHT to a compromised address and immediately transfer them away.

In order to “repair” this, they have to allow to change the destination address (which they deliberately did not want to allow in the first place). And they have to find a way to ensure that the legitimate user does this change which is quite hard when the address is already compromised.

Small complication is also that they decided to move the still unthawed NIGHT to individual addresses with the first redemption. So, a lot of NIGHT will have to be moved from a lot of addresses when and if they come up with a solution.

2 Likes

Now i get somewhere thank u hepta bro
So its a problem with night and the ada in those wallets is safe???
Or also in danger

1 Like

No, nothing NIGHT-specific about it at all.

All assets in the affected addresses are at risk, including the ADA themselves.

The only NIGHT-specific thing here is that redemption was built in a way that insists to continue to use compromised addresses even if you know they are compromised.

Addresses are only affected if you used SecondFi at all (don’t know if it was already introduced when it was still called Yoroi) and if you did a transaction with SecondFi.
The way they created signatures was broken in a way that made it very easy to compute the private key for that specific address from it.
If you didn’t use SecondFi, you are not affected. If you didn’t sign a transaction from an address, that address is not affected. If you didn’t delegate or withdraw rewards, your stake key is not affected.
They have built a tool to check if addresses are affected: https://checker.secondfi.io/

As the message from Midnight states: If you never used SecondFi, this doesn’t concern you at all and they are very sorry, but it is prudent to stop all redemptions and try to find a way because hundreds of users are affected.

2 Likes

Goodmorning,
Final thing​:face_with_peeking_eye:: who is the culprit in this affaire
Did cardano do some wrong……test not to the bone this new yoroi thing?? Brought it out too soon??
Those wallet holders did some wrong??
If the fault is @ charles H. You think compensation is fair???
Anyway night is @ hold and dont like it​:cry:
Thanks hepta

Well, rolling your own cryptographic libraries is not really best practice.
And then deviating from the standards on how to do it, is even worse.

There is no entity “Cardano” which could do something wrong or right.

The entity responsible for Yoroi/SecondFi is Emurgo.

Shouldn’t have happened. Either by guardrails before even starting implementation or by code reviews. Not sure if it could have been caught in testing (since it behaved correctly, testing for secrets being leaked in one of a gazillion different ways is not really possible).

I personally think that Hoskinson is a useless piece of shit. But he has nothing to do with this. Emurgo is a completely different company than IOG. And none of those companies “is” Cardano.

Emurgo promised to make users whole. Let’s see if and how they will.

1 Like

Official announcement (here on Discord):

Glacier Drop redemptions will resume today at 17:00 UTC.

… i.e. already. Corresponding blog post: Glacier Drop Redemptions Update saying the same thing (it’s resumed).

2 Likes

Thats good News,
Hope they found out the flaw @secondfi and its solid and safe for it users