
The Wanchain bridge was hacked in 8 minutes — 515M NIGHT tokens stolen, Midnight fell 35%
The Wanchain cross-chain bridge, connecting Cardano and BNB Chain, was exploited on July 21, 2026: attackers drained 515.2 million NIGHT tokens — the native asset of Midnight, a privacy-focused network built on Cardano technology — from the bridge's treasury. The stolen amount is estimated at roughly $10 million.
How the Attack Unfolded
According to blockchain security firm BlockSec, the entire attack took just eight minutes and consisted of four sequential transactions. The vulnerability was found in the TreasuryCheck validator — specifically, in how it encoded signature messages. The root cause was the raw concatenation of 14 variable-length redemption fields used during withdrawals, without delimiters between them: this meant different combinations of fields could produce an identical byte string, and therefore the same hash and the same signature, which attackers were able to reuse.
The Cardano-BNB Chain bridge for NIGHT was originally launched by Wanchain back in December 2025, letting users move the token between the two networks through Wanchain's cross-chain infrastructure.
Market and Midnight Network Response
The NIGHT token crashed 35% over 24 hours on the news, falling to roughly $0.0174-0.0186 according to CoinGecko. The Midnight Foundation stressed that the incident was isolated entirely to the Wanchain Cardano-BNB bridge and had nothing to do with the Midnight network itself: the protocol, validators, consensus mechanism, and core infrastructure continued operating normally throughout.
Why It Matters
The incident is another reminder that cross-chain bridges remain one of the most vulnerable points in blockchain infrastructure: even when the underlying network (Midnight, in this case) functions flawlessly, risk can concentrate specifically in the intermediary layer responsible for moving assets between ecosystems. The fact that the vulnerability traced back to the signature-validation logic itself, rather than a more obvious attack vector, underscores how thoroughly bridge code needs to be audited before it sees wide use.
This material is for informational purposes only and is not investment advice.

Comments (0)
No comments yet — be the first!
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
234AI





