Serious question: How was hyperfree ever in possession of any user nsecs?
If you authenticated your existing npub using a browser extension or only provided them with a public key, that could not have happened.
Are the only users affected ones who generated their keys using this app?