Loading prices...
All news
The Wanchain bridge was hacked in 8 minutes — 515M NIGHT tokens stolen, Midnight fell 35%

The Wanchain bridge was hacked in 8 minutes — 515M NIGHT tokens stolen, Midnight fell 35%

July 21, 2026 · 07:00 PM
0

The Wanchain cross-chain bridge, connecting Cardano and BNB Chain, was exploited on July 21, 2026: attackers drained 515.2 million NIGHT tokens — the native asset of Midnight, a privacy-focused network built on Cardano technology — from the bridge's treasury. The stolen amount is estimated at roughly $10 million.

How the Attack Unfolded

According to blockchain security firm BlockSec, the entire attack took just eight minutes and consisted of four sequential transactions. The vulnerability was found in the TreasuryCheck validator — specifically, in how it encoded signature messages. The root cause was the raw concatenation of 14 variable-length redemption fields used during withdrawals, without delimiters between them: this meant different combinations of fields could produce an identical byte string, and therefore the same hash and the same signature, which attackers were able to reuse.

The Cardano-BNB Chain bridge for NIGHT was originally launched by Wanchain back in December 2025, letting users move the token between the two networks through Wanchain's cross-chain infrastructure.

Market and Midnight Network Response

The NIGHT token crashed 35% over 24 hours on the news, falling to roughly $0.0174-0.0186 according to CoinGecko. The Midnight Foundation stressed that the incident was isolated entirely to the Wanchain Cardano-BNB bridge and had nothing to do with the Midnight network itself: the protocol, validators, consensus mechanism, and core infrastructure continued operating normally throughout.

Why It Matters

The incident is another reminder that cross-chain bridges remain one of the most vulnerable points in blockchain infrastructure: even when the underlying network (Midnight, in this case) functions flawlessly, risk can concentrate specifically in the intermediary layer responsible for moving assets between ecosystems. The fact that the vulnerability traced back to the signature-validation logic itself, rather than a more obvious attack vector, underscores how thoroughly bridge code needs to be audited before it sees wide use.

This material is for informational purposes only and is not investment advice.

Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!