Key Takeaways
- On July 21, 2026, malicious actors exploited the Wanchain-managed Cardano-to-BNB Chain bridge, extracting approximately 515 million NIGHT tokens valued at roughly $13 million.
- The vulnerability stemmed from a critical signature reuse defect that enabled hackers to convert an authorized withdrawal of ~3,110 NIGHT into over 203 million NIGHTârepresenting a staggering 65,000x multiplication.
- Following mass liquidation of stolen assets on decentralized trading platforms, NIGHT plummeted over 30% to an all-time low near $0.016.
- The Midnight Foundation emphasized that its primary blockchain infrastructure, validator network, and consensus mechanisms remained completely secureâthe compromise was limited exclusively to the bridge platform.
- Wanchain immediately suspended bridge operations and announced plans to release a comprehensive technical analysis of the incident.
The cryptocurrency industry witnessed another significant bridge security breach when Wanchain’s Cardano-to-BNB Chain cross-chain gateway fell victim to a sophisticated exploit on July 21, 2026. The perpetrators successfully siphoned approximately 515 million NIGHT tokens from the bridge’s treasury, representing a financial loss of approximately $13 million.
Market reaction was swift and severe. Within a single day, NIGHT experienced a precipitous decline exceeding 30%. According to CoinGecko tracking data, the token plunged to approximately $0.0186, approaching historical lows.

Responding to the security incident, Wanchain immediately disabled the bridge functionality. The development team committed to publishing a comprehensive incident report with full technical details.
Technical Breakdown of the Exploit
Cybersecurity specialists at BlockSec Phalcon traced the vulnerability to a fundamental design weakness in the TreasuryCheck validator component powering the Wanchain bridge infrastructure.
The bridge’s message signing mechanism concatenated 14 variable-length data fields directly without implementing separators or length indicators. This architectural oversight created a collision vulnerability where disparate field combinations could generate identical byte sequences and corresponding hash values.
Exploiting this structural weakness, the attacker executed a signature reuse manipulation. A legitimate authorization signature originally intended to approve approximately 3,110 NIGHT was successfully recycled to validate a withdrawal exceeding 203 million NIGHT in one transactionâeffectively achieving a 65,000-fold amplification.
The illicitly obtained tokens were immediately liquidated across various decentralized exchange platforms, precipitating the dramatic market downturn.
BlockSec researchers observed that while the smart contract already incorporated Cardano’s SerialiseData function, the bridge implementation failed to utilize it during signature hash construction. Proper implementation of this function would have almost certainly thwarted the attack.
Midnight’s Core Network Remains Intact
The Midnight Foundation moved swiftly to clarify its position and reassure stakeholders. Officials emphasized that the security breach was entirely contained within Wanchain’s external bridge solution.
“The incident is isolated to the Wanchain CardanoâBNB bridge and does not involve the Midnight Network itself,” the foundation said.
Throughout the entire security incident, Midnight’s underlying protocol, validator infrastructure, consensus architecture, and fundamental network components maintained uninterrupted operation.
The compromised assets represented tokens stored within the bridge’s treasury reserve to facilitate cross-blockchain transfersânot an alteration to NIGHT’s maximum supply cap of 24 billion tokens. The stolen 515 million tokens constitute approximately 2% of the total circulating supply.
Midnight executed its mainnet deployment in March 2026. The platform functions as a privacy-centric Cardano partner chain implementing a dual-token economic framework centered on NIGHT and DUST.
The NIGHT token had experienced appreciation exceeding 20% surrounding the mainnet activation. This bridge security failure has eliminated a significant portion of those accumulated gains.
2026’s Continuing Bridge Security Crisis
The Wanchain compromise represents yet another chapter in 2026’s troubling narrative of bridge-related security failures. Humanity Protocol experienced a devastating $31 million breach when threat actors compromised multisig wallet credentials via an employee’s infected laptop. Gnosis Pay disclosed a $1.8 million attack impacting more than 5,000 user wallets, though the platform ultimately provided complete restitution to all affected parties.
Prior to this incident, Wanchain had maintained operations spanning dozens of blockchain networks for over eight years without experiencing a major security compromise.
Critical developments to monitor include Wanchain’s forthcoming comprehensive technical disclosure, potential victim compensation frameworks, and whether NIGHT’s market valuation and blockchain transaction metrics achieve stabilization in upcoming trading sessions.





