TLDR
- Exchanges froze attacker-linked wallets after Wanchain’s Cardano-BNB bridge lost 515 million NIGHT tokens during exploit.
- BlockSec traced the breach to possible signature reuse inside Wanchain’s TreasuryCheck validator message encoding design.
- Attackers reportedly extracted over 203 million NIGHT in one transaction using field-boundary manipulation techniques alone.
- Midnight Foundation said the incident was isolated and did not breach its core blockchain network.
- NIGHT fell more than 30% after stolen tokens were sold across decentralized exchanges, adding pressure.
Wanchain’s Cardano-BNB bridge exploit has drawn fresh scrutiny after attackers drained 515 million NIGHT tokens, worth about $13 million. Exchanges moved to freeze linked wallets and restrict transfers, while Midnight said its core network remains secure as Wanchain investigates the breach and prepares a full post-mortem for users and partners.
Exchanges Move to Restrict Stolen NIGHT
Wanchain said it has been working with exchange partners after the attack on the Cardano-BNB bridge. The company said several platforms acted quickly to restrict movement of assets tied to the incident.
The list includes KuCoin, Kraken, Binance, Bybit, OKX, and MEXC. Wanchain said those exchanges introduced precautionary measures, including temporary account freezes and wallet blacklists linked to the attacker.
Some platforms also suspended NIGHT deposits and withdrawals where needed. Wanchain said the coordinated response reduces the attacker’s ability to move or sell the stolen funds.
The attack reportedly drained about 515 million NIGHT from the bridge treasury, with the tokens valued near $13 million. NIGHT later fell more than 30% and traded near a record low around $0.016.
BlockSec Points to Signature Reuse Flaw
On-chain security firm BlockSec Phalcon traced the reported exploit to a possible flaw in the Wanchain TreasuryCheck validator. The firm said the validator used non-injective signed-message encoding when building transaction approval messages.
The signed message was created by joining 14 variable-length redeemer fields without delimiters or length prefixes. That structure could allow different field combinations to create the same byte string and hash.
BlockSec said the design may have allowed signature reuse. The attacker allegedly reused a valid signature tied to about 3,110 NIGHT and extracted more than 203 million NIGHT in one transaction.
That single transaction created a roughly 65,000x token extraction effect through field-boundary manipulation. The attacker later sold large amounts of NIGHT across decentralized exchanges, adding pressure to the token price.
Wanchain confirmed the bridge was taken offline while the investigation continues. The team said it is preparing a detailed update on the incident and its response plan.
Midnight Says Core Network Was Not Breached
Midnight Foundation said the incident was limited to third-party bridge infrastructure and did not affect the Midnight protocol. The foundation described the event as an “isolated third-party bridge incident.”
The foundation said the Midnight network, validators, consensus mechanism, and core infrastructure remain secure. It also said the incident did not involve the NIGHT asset itself or the Midnight blockchain.
The affected tokens represented about 2% of NIGHT’s total supply of roughly 24 billion tokens. The movement came from the bridge treasury, not from a protocol-level mint or a direct breach of Midnight’s chain.
The incident has renewed attention on cross-chain bridge risks in 2026. For NIGHT holders, the next updates will center on Wanchain’s post-mortem, exchange restrictions, possible recovery steps, and when bridge services may resume.





