Breaking: Wanchain Cardano Bridge Breached in $13M Hack, 515M NIGHT Tokens Drained
Highlights
- Attackers drained ~515 million $NIGHT (~$13M) from the Wanchain-operated Cardano–BNB Chain bridge, sending the token down 30% to a record low near $0.016.
- BlockSec Phalcon traced the exploit to a signature reuse flaw that let attackers turn a ~3,110 NIGHT signature into 203M+ NIGHT, a 65,000x inflation effect.
- The Midnight Foundation confirmed the breach was isolated to third-party bridge infrastructure, leaving Midnight's network, validators, and consensus fully secure.
A major exploit hit the Wanchain-operated bridge connecting Cardano and BNB Chain on July 21, 2026. Attackers drained approximately 515 million $NIGHT tokens, worth around $13 million, from the bridge treasury. This sent $NIGHT tumbling more than 30% to a record low near $0.016. Wanchain has taken the bridge offline and is investigating. The Midnight Foundation confirmed the Midnight network itself remains fully secure.
Signature Reuse Flaw Allowed 65,000x Token Inflation in Single Transaction
The Wanchain bridge has operated across dozens of blockchains for over eight years without a major incident. Its integration with Cardano was part of a broader push to expand Cardano’s cross-chain capabilities.
When Cardano founder Charles Hoskinson announced the Midnight token launch. The project drew significant attention as a privacy-first sidechain within the Cardano ecosystem.
The bridge later enabled deeper interoperability for assets like RLUSD on Cardano through its cross-chain bridge integration. The aim is to reinforce its role as a key infrastructure player.
On-chain forensics firm BlockSec Phalcon identified the root cause as a non-injective signed-message encoding flaw in the TreasuryCheck validator.
The Wanchain bridge built its signed message by raw concatenating 14 variable-length redeemer fields without delimiters or length prefixes. This allowed different field-value combinations to produce an identical byte string and hash, enabling signature reuse attacks.
Wanchain @wanchain_org Cardano bridge was reportedly being attacked, with ~515M $NIGHT drained from the bridge Treasury.
Our initial investigation suggests that the root cause seems to be a non-injective signed-message encoding in the TreasuryCheck validator. The signed message… https://t.co/bnWEnw3Dxc pic.twitter.com/PQFAN6lRn9
— BlockSec Phalcon (@Phalcon_xyz) July 21, 2026
The attacker reused a legitimate signature that authorized only ~3,110 NIGHT to extract over 203 million NIGHT in a single transaction, a roughly 65,000x inflation effect driven by field-boundary manipulation.
They then dumped the drained tokens on decentralized exchanges, triggering the sharp price collapse.
Analysts tracking the NIGHT token price outlook had previously flagged Midnight’s growing traction as a tailwind for Cardano; this incident now tests investor conviction in that thesis.
Wanchain’s team confirmed the breach, took the bridge offline, and stated it is preparing a detailed update.
The Midnight Foundation was quick to clarify that the exploit was fully isolated to third-party bridge infrastructure and had no impact on the Midnight network, its validators, consensus mechanism, or core protocol.
Cross-Chain Bridge Risk Resurfaces, But Midnight Protocol and Cardano Remain Unscathed
Community reaction on X has been swift and largely clear-eyed: the exploit reflects a bridge security design failure, not a flaw in Cardano or the Midnight protocol.
Midnight’s consensus, validators, and core infrastructure were never at risk. The breach was confined entirely to the Wanchain-operated third-party bridge layer, a critical distinction investors should not overlook.
Roughly 2% of NIGHT’s total supply, approximately 515 million of ~24 billion tokens, was affected through the bridge treasury, not from circulating supply.
That context matters. The token’s sharp drop reflects panic selling, not a fundamental compromise of the network or its utility.
Investors who had been tracking Cardano’s privacy ecosystem momentum may view the dip as a tactical entry point, given the underlying protocol remains fully intact and operational.
The incident also arrives as Wanchain is gaining recognition in interoperability circles as a potential cross-chain listing candidate for major exchanges.
That trajectory is now likely paused until a credible post-mortem and recovery plan are published.
Security notice regarding the Cardano ↔ BNB Chain Bridge. pic.twitter.com/tUrSnXg5VN
— Wanchain (@wanchain_org) July 21, 2026
This is not the first time bridge infrastructure has buckled under the weight of a smart contract flaw in 2026. Humanity Protocol suffered a $31M exploit a month ago after an employee’s laptop was hacked. The hack granted attackers access to multisig wallet keys that controlled its Ethereum and BNB Chain bridges, enabling unlimited token minting.
Also in June 2026, Gnosis Pay confirmed a $1.8M attack that hit 5,281 wallets via a Zodiac module vulnerability present since 2023.
Unlike many exploits, Gnosis Pay refunded 100% of user funds, a response that set a positive precedent. CoinGape covered how Gnosis Pay handled the $1.8M crypto attack and the security changes the platform introduced in response.
Taken together, the Wanchain incident fits a recurring 2026 pattern of bridge and infrastructure exploits that punish connected tokens severely while leaving core Layer-1 protocols untouched.
For $NIGHT holders and Cardano bulls, the key signals to watch now are Wanchain’s forthcoming post-mortem, any compensation or bridge resumption timeline, and whether on-chain NIGHT activity stabilizes in the days that follow.
If you’re hunting for early-stage opportunities, check out our list of the best crypto presales.











