Key Takeaways
- Approximately 515 million NIGHT tokens valued at $13 million were stolen from Wanchain’s Cardano-to-BNB Chain bridge infrastructure on July 21, 2026.
- Exploiters leveraged a critical signature reuse vulnerability, transforming an authorization for roughly 3,110 NIGHT into more than 203 million tokens — representing a 65,000x amplification.
- The NIGHT token price plummeted over 30%, reaching an all-time low around $0.016 following mass selling of the compromised assets on DEX platforms.
- Midnight Foundation verified that its blockchain infrastructure, validator network, and consensus mechanisms remained completely secure — the vulnerability was confined exclusively to bridge operations.
- Bridge services have been suspended by Wanchain while investigators work on a comprehensive technical analysis report.
On July 21, 2026, a significant security breach targeted the Wanchain-managed bridge connecting Cardano to BNB Chain. Malicious actors successfully extracted approximately 515 million NIGHT tokens from the bridge’s treasury, representing roughly $13 million in market value.
Market reaction was swift and severe, with NIGHT experiencing a price decline exceeding 30% in the following day. According to CoinGecko tracking data, the token reached approximately $0.0186, marking a new historical low point.

Following confirmation of the security incident, Wanchain immediately disabled bridge functionality. The development team announced plans to release a comprehensive incident report with full technical disclosure.
Technical Breakdown of the Exploit
Security researchers at BlockSec Phalcon pinpointed a critical vulnerability within the TreasuryCheck validator component deployed by Wanchain’s bridge architecture.
The fundamental issue stemmed from how the bridge constructed signed messages. It concatenated 14 variable-length data fields directly without incorporating delimiters or length indicators. This design flaw created a scenario where different input combinations could generate identical byte sequences and resulting hash values.
Exploiting this weakness, attackers executed a signature replay attack. They repurposed a valid signature originally authorizing approximately 3,110 NIGHT tokens to instead withdraw more than 203 million NIGHT in one transaction — achieving an approximately 65,000-fold multiplication effect.
The compromised tokens were subsequently liquidated across various decentralized exchange platforms, creating intense selling pressure that drove the dramatic price decline.
BlockSec analysts observed that the smart contract already incorporated Cardano’s SerialiseData function, but the bridge implementation failed to utilize it during signature hash construction. Proper implementation of this function would have effectively prevented this attack vector.
Midnight’s Core Infrastructure Remains Intact
The Midnight Foundation moved quickly to clarify the scope of the incident. Official statements emphasized that the security compromise was entirely limited to Wanchain’s external bridge solution.
“The incident is isolated to the Wanchain Cardano–BNB bridge and does not involve the Midnight Network itself,” the foundation said.
Throughout the entire security event, Midnight’s underlying protocol, validator operations, consensus architecture, and fundamental infrastructure maintained complete operational integrity.
The stolen assets originated from the bridge’s reserve holdings used to facilitate cross-chain transactions — not from any modification to NIGHT’s maximum supply cap, which remains fixed at 24 billion tokens. The affected volume of approximately 515 million tokens represents roughly 2% of the total token supply.
Midnight activated its mainnet in March 2026. The network functions as a privacy-oriented partner chain within the Cardano ecosystem, employing a dual-token economic model centered on NIGHT and DUST tokens.
Following the mainnet deployment, NIGHT experienced price appreciation exceeding 20%. The bridge compromise has eliminated a significant portion of these earlier gains.
2026’s Growing Bridge Security Crisis
This Wanchain incident represents another chapter in an expanding series of bridge-related security failures throughout 2026. Humanity Protocol experienced a $31 million loss when attackers compromised multisig wallet credentials through an infected employee device. Gnosis Pay disclosed a $1.8 million breach impacting more than 5,000 user wallets, though the platform provided complete reimbursement to all victims.
Prior to this security breach, Wanchain had maintained cross-chain operations spanning dozens of blockchain networks for more than eight years without experiencing a major security incident.
Critical upcoming developments include Wanchain’s detailed technical post-mortem publication, potential victim compensation strategies, and whether NIGHT can achieve price stabilization and recover on-chain activity metrics in upcoming trading sessions.



