Quick Summary
- On July 21, 2026, malicious actors exploited Wanchain’s Cardano-to-BNB Chain bridge infrastructure, extracting approximately 515 million NIGHT tokens valued at roughly $13 million.
- The vulnerability stemmed from a critical signature reuse weakness that enabled attackers to amplify a legitimate ~3,110 NIGHT authorization into over 203 million NIGHTārepresenting a 65,000x multiplication effect.
- Following the exploit and subsequent token liquidation on decentralized platforms, NIGHT experienced a price collapse exceeding 30%, reaching approximately $0.016āa new all-time low.
- Midnight Foundation issued statements clarifying that its primary blockchain infrastructure, including validators and consensus mechanisms, remained completely secure and operational.
- The compromised bridge has been disabled by Wanchain, with a comprehensive technical analysis report currently in development.
A significant security vulnerability in Wanchain’s cross-chain bridge infrastructure resulted in substantial token losses on July 21, 2026. The bridge connecting Cardano to BNB Chain was compromised, enabling attackers to siphon approximately 515 million NIGHT tokens from the treasury reserves, representing a monetary loss of around $13 million.
The immediate market impact was severe, with NIGHT declining over 30% in value within a single day. According to CoinGecko tracking data, the token reached levels around $0.0186, approaching its lowest recorded valuation.

Following confirmation of the security incident, Wanchain immediately suspended bridge operations. The development team announced plans to release comprehensive documentation detailing the breach and remediation efforts.
Technical Analysis of the Exploit Method
Cybersecurity specialists at BlockSec Phalcon discovered the vulnerability within the TreasuryCheck validator component integrated into Wanchain’s bridge architecture.
The fundamental issue arose from how the bridge constructed its cryptographic message signatures. The system concatenated 14 variable-length data fields directly without implementing delimiters or length indicators. This structural weakness created collision scenarios where disparate field value combinations could generate identical byte sequences and resulting hash values.
This design flaw created an opportunity for signature replay exploitation. Attackers successfully repurposed a valid cryptographic signatureāoriginally authorizing approximately 3,110 NIGHT tokensāto instead authorize withdrawal of more than 203 million NIGHT in one transaction. This represented an amplification factor of roughly 65,000 times the legitimate authorization.
The compromised tokens were subsequently liquidated through decentralized exchange platforms, creating substantial selling pressure that drove the dramatic price decline.
BlockSec’s analysis revealed that while the smart contract implementation already included Cardano’s SerialiseData functionality, the bridge protocol failed to utilize this function during signature hash construction. Proper implementation of this existing feature would have effectively prevented the exploitation.
Midnight Protocol Remains Secure
The Midnight Foundation moved swiftly to clarify the scope of the security incident. Official statements emphasized that the vulnerability existed exclusively within Wanchain’s external bridge solution and did not extend to Midnight’s core infrastructure.
“The incident is isolated to the Wanchain CardanoāBNB bridge and does not involve the Midnight Network itself,” the foundation said.
Throughout the entire incident, Midnight’s blockchain protocol, validator network, consensus architecture, and fundamental infrastructure maintained complete operational integrity without interruption.
The compromised assets represented tokens allocated within the bridge’s treasury system to facilitate cross-chain transaction capabilitiesānot an unauthorized modification to NIGHT’s maximum token supply, which remains fixed at 24 billion tokens. The stolen amount of approximately 515 million tokens constitutes roughly 2% of the total circulating supply.
Midnight successfully deployed its mainnet platform in March 2026. The network functions as a privacy-centric partner chain within the Cardano ecosystem, utilizing a dual-token economic framework centered on NIGHT and DUST tokens.
The NIGHT token had appreciated more than 20% following the mainnet deployment. However, the bridge security incident has eliminated a significant portion of those previous valuation gains.
Part of Broader 2026 Security Challenges
This Wanchain security incident represents one element within a larger trend of bridge-related vulnerabilities throughout 2026. Humanity Protocol experienced a $31 million compromise when threat actors obtained multisig wallet credentials via a compromised employee device. Gnosis Pay documented a $1.8 million attack impacting more than 5,000 user wallets, though the platform subsequently reimbursed all affected accounts completely.
Prior to this breach, Wanchain had maintained cross-chain operations spanning numerous blockchain networks for more than eight years without experiencing a significant security incident.
Market participants and stakeholders will be monitoring several critical developments: the release of Wanchain’s complete technical investigation report, potential user compensation frameworks, and whether NIGHT’s market valuation and blockchain activity metrics achieve stabilization in upcoming trading sessions.


