Wanchain Cardano–BNB Bridge Hit by Exploit Draining 515M NIGHT Tokens
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Wanchain’s Cardano–BNB bridge reportedly lost around 515 million NIGHT tokens in a suspected security exploit.
- Midnight Foundation said the attack affected third-party bridge infrastructure, while its blockchain and core systems remained secure.
- BlockSec linked the incident to unclear transaction data formatting that may have allowed signature reuse.
The Wanchain Cardano–BNB bridge was reportedly attacked, with around 515 million NIGHT tokens taken from its treasury. The incident affected NIGHT tokens held within the third-party bridge. However, the Midnight Foundation said the attack did not compromise the Midnight blockchain or its main systems.
The Midnight Foundation first addressed the incident on July 20. It said it was aware of reports involving bridged NIGHT tokens on Wanchain’s Cardano-to-BNB bridge. The foundation noted that the issue appeared to affect the bridge infrastructure rather than the Midnight network itself.
The foundation said it was monitoring the situation and working with its partners to confirm what had happened. It also advised users to follow official updates and remain careful about phishing links, fake accounts and impersonation scams.
🚨 Community Update:
We are aware of reports concerning an incident involving the Wanchain Cardano to BNB bridge affecting bridged NIGHT.
Based on the information currently available, this appears to relate to cross-chain bridge operations and not the @MidnightNtwrk itself. We…
— Midnight Foundation (@midnightfdn) July 20, 2026
Midnight Says Its Main Network Remains Secure
In a later update, the Midnight Foundation provided more details about the incident. It said the problem was limited to Wanchain’s Cardano–BNB bridge, which is separate from Midnight’s main blockchain systems. According to the foundation, Midnight’s protocol, validators, consensus system and core infrastructure remained secure and continued to work normally. It also said the incident did not result from a problem with the NIGHT token or the Midnight blockchain.
Instead, the incident involved third-party infrastructure used to move tokens between Cardano and BNB Chain. Cross-chain bridges allow users to transfer tokens from one blockchain to another. To support these transfers, bridges often lock tokens on one network and issue a matching version on another. The Midnight Foundation said it remained in contact with Wanchain as the investigation continued.
BlockSec Finds Possible Flaw in Bridge Validator
After Midnight’s clarification, blockchain security firm BlockSec Phalcon shared its initial technical findings on July 21. BlockSec said around 515 million NIGHT tokens were reportedly drained from the bridge treasury. Its early investigation pointed to a possible weakness in the TreasuryCheck validator. This validator checks transaction details before allowing funds to move.
According to BlockSec, the validator created a signed message by joining 14 data fields together. However, it did not place separators or length markers between those fields. As a result, two different sets of transaction details could create the same final data string. They could then produce the same hash, which works like a digital fingerprint. An attacker may have used this weakness to reuse a valid signature with different transaction details.
BlockSec reached its initial conclusion after reviewing the bridge’s on-chain Plutus V2 code. The firm also examined the redeemer used in the reported attack transaction. A redeemer contains information that a Cardano smart contract checks before approving a transaction.
Clear Data Boundaries May Have Prevented the Attack
BlockSec also found that the bridge code contained Cardano’s SerialiseData function. However, the contract did not use it when creating the signature hash. Using properly serialized data would have created clear boundaries between each transaction field. According to BlockSec, this could have stopped different sets of values from producing the same signed message.
Wanchain @wanchain_org Cardano bridge was reportedly being attacked, with ~515M $NIGHT drained from the bridge Treasury.
Our initial investigation suggests that the root cause seems to be a non-injective signed-message encoding in the TreasuryCheck validator. The signed message… https://t.co/bnWEnw3Dxc pic.twitter.com/PQFAN6lRn9
— BlockSec Phalcon (@Phalcon_xyz) July 21, 2026
The findings are still part of an initial investigation. Wanchain will need to complete its review before confirming the exact cause, full impact, and next steps.
The incident comes as cross-chain platforms face renewed security concerns. Allbridge Core recently suspended its services after a $1.65 million flash loan attack affected its Solana liquidity pools. Unlike the reported Wanchain incident, the Allbridge attack involved the manipulation of pool prices rather than a direct weakness in the bridge itself.
#PeckShieldAlert @Allbridge_io Core was exploited for ~$1.65M.
The exploiter has bridged the stolen funds from #Solana to #Ethereum pic.twitter.com/ZOZysmJcAH
— PeckShieldAlert (@PeckShieldAlert) July 20, 2026
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







