Loading market data...

Wanchain Bridge Exploit Drains 515M Midnight NIGHT Tokens, Token Plunges 30%

Wanchain Bridge Exploit Drains 515M Midnight NIGHT Tokens, Token Plunges 30%

A bridge connected to the Cardano ecosystem was hit by an exploit on July 20, draining roughly 515 million Midnight NIGHT tokens from infrastructure operated by Wanchain. The stolen tokens were pulled from a Cardano-side lock address backing NIGHT bridged to BNB Chain, leaving only a fraction of the bridge’s previous reserves. NIGHT token fell more than 30% during the fallout, touching a record low near $0.015; the stolen assets were worth roughly $9 million to $10 million at the time of the sell-off.

Inside the signature-reuse exploit

Wanchain suspended the affected Cardano-to-BNB Chain bridge and began investigating the incident. Blockchain security firm BlockSec said its preliminary analysis pointed to a possible problem in the TreasuryCheck validator’s signed-message encoding. That flaw could have allowed a previously valid signature to be reused with different transaction data — essentially letting an attacker replay a signature to authorize unauthorized transfers.

Exchanges move to freeze stolen tokens

Exchanges including Binance, Kraken, KuCoin, Bybit, OKX, Gate, and MEXC joined efforts to limit movement of the stolen assets. They froze or restricted accounts, blacklisted wallets, and suspended NIGHT deposits and withdrawals where necessary. The coordinated response suggests the industry is getting faster at containing these incidents, though the attacker had already dumped a significant portion of the haul.

Midnight and Hoskinson on the breach

The Midnight Foundation stated the breach was confined to the third-party bridge infrastructure and did not disrupt Midnight’s protocol, validator network, consensus system, or core infrastructure. The NIGHT smart contract on Cardano continued functioning. Cardano founder Charles Hoskinson said organizations across the ecosystem formed a 'war room' to monitor the situation, bringing together Midnight, Input Output, Intersect, and other groups. Hoskinson argued that bridges are the most vulnerable part of the crypto stack because they depend on external verification or trust outside the networks they connect, and noted that more than $2 billion in crypto has been stolen from bridges historically. He defended Cardano’s emphasis on formal methods, peer review, and protocol design, but said these practices reduce but do not eliminate attack vectors, comparing it to being 90% resistant to a deadly disease. Hoskinson pointed to future bridge designs incorporating recursive or folded zero-knowledge proofs, trusted execution environments, and multisignature controls to reduce dependence on external validation. He also highlighted Midnight Passport, an identity and selective-disclosure system that could allow users to establish ownership of wallets without publicly exposing all information.

This isn’t the first security hiccup for Midnight this summer. The project temporarily suspended Glacier Drop redemptions in late June after a separate security incident affecting some Cardano wallets associated with SecondFi. Redemptions resumed on July 9 after concluding that its own infrastructure was not exposed. Hoskinson stated that audits would be required to establish 'ground truth' around the failure and responsibility for the incident. Those audits haven’t been announced yet, but they’ll be the next concrete step in figuring out exactly what went wrong — and who’s on the hook.