Wanchain Cardano Bridge Suffers Major Exploit, $10 Million in NIGHT Tokens Drained

Transfer breakdown and wallet ties: the 515.2 million NIGHT were moved in four transfers of approximately 203.0m, 129.6m, 120.4m, and 62.1m NIGHT from the Wanchain Cardano bridge between 14:46 and 14:55 UTC on July 20, 2026. Investigators flagged two wallets, W1 and W2, likely controlled by the same actor; W1 first sent 1,000 ADA to W2 before transferring about 200.06m NIGHT to W2, which later returned 100.31m NIGHT plus ADA and USDCx. W1 then began selling roughly 300m NIGHT across DEXs.
Only NIGHT were withdrawn while other assets remained in the bridge: although the Wanchain bridge held other liquid assets such as Mynth, XER, and WMT, on-chain analysis indicated that only NIGHT tokens were drained during the incident, with no reported withdrawals of the other assets.
Root-cause detail: BlockSec’s preliminary analysis points to a non-injective encoding flaw in the TreasuryCheck validator, caused by concatenating 14 fields without separators or length prefixes, enabling potential signature reuse. BlockSec also notes the signing did not appear to use Cardano’s SerialiseData function for the signature hash, suggesting a more structured encoding could have prevented this ambiguity.
Market impact and value: the exploit drove NIGHT’s price down by roughly 30–40% intraday, with BlockSec estimating the drained amount equating to about $10 million in realized value at prevailing prices around $0.0195 per NIGHT.
Progression of liquidation: BlockSec indicated roughly 90% of the stolen NIGHT was liquidated through DEXs and DeFi protocols, highlighting rapid on-ramp activity even as investigations continue and the post-incident postmortems are being prepared.
Hackers drained 515.2 million NIGHT tokens — worth roughly $10 million — from Wanchain's Cardano-to-BNB Chain bridge on July 20, 2026, in one of the largest Cardano bridge exploits on record. The theft happened in just eight minutes, across four separate transfers, and sent NIGHT's price crashing 30–40% within hours, according to CryptoTimes.
Security firm BlockSec's Phalcon monitor detected the breach and flagged a flaw in the bridge's smart contract code as the likely cause. The Midnight Foundation, which issues NIGHT, stressed that its core network was not compromised. The exploit targeted only third-party bridge infrastructure, Crypto.news reported.
The attack unfolded between 14:46 and 14:55 UTC. The hacker moved NIGHT in four chunks: roughly 203.0 million, 129.6 million, 120.4 million, and 62.1 million tokens, according to CoinGape. All four transfers came from the Wanchain Cardano bridge treasury. No other assets on the bridge — including Mynth, XER, and WMT tokens — were touched.
On-chain investigators flagged two wallets, labeled W1 and W2, likely controlled by the same actor. W1 first sent 1,000 ADA to W2, then transferred about 200.06 million NIGHT to W2. W2 later returned 100.31 million NIGHT plus ADA and USDCx back to W1. W1 then began selling roughly 300 million NIGHT across decentralized exchanges, according to CryptoTimes.
BlockSec's preliminary analysis points to a non-injective encoding flaw in the bridge's TreasuryCheck validator. The validator concatenated 14 data fields with no separators or length markers between them. That design allowed an attacker to reassemble the same raw data in different ways and reuse a valid signature to authorize unauthorized transactions, CoinGabbar reported.
BlockSec also noted the signing process did not appear to use Cardano's built-in SerialiseData function for the signature hash. Using a more structured encoding method could have prevented the ambiguity. In plain terms: the code did not label its data clearly enough, so the attacker found a way to trick it into approving fake withdrawals.
BlockSec estimated that about 90% of the stolen NIGHT was quickly sold through DEXs and DeFi protocols before investigators could act. At a prevailing price of roughly $0.0195 per token, the 515.2 million NIGHT were worth around $10 million in realized value, according to CryptoTimes.
The rapid sell-off hit NIGHT's market hard. The token fell 30–40% intraday, reflecting both the direct selling pressure and broader panic among holders. CoinGape estimated total losses between $10 million and $13 million depending on the price point used for the calculation.
The Midnight Foundation moved quickly to clarify the scope of the breach. The foundation said the Midnight network itself — the privacy-focused blockchain that issues NIGHT — was never at risk. The exploit was limited to Wanchain's third-party bridge infrastructure connecting Cardano and BNB Chain, Crypto.news reported.
Security researchers and authorities are still investigating the full scope of the attack. The incident adds to a growing list of cross-chain bridge hacks and renews calls for stronger encoding and signing standards in bridge contracts. A full post-incident report from BlockSec is expected as the investigation continues, according to CoinGabbar.
Publishers
14
Articles
2
Reach
16