TLDR
- Attackers drained ~515 million NIGHT tokens worth around $13M from the Wanchain-operated Cardano-to-BNB Chain bridge on July 21, 2026.
- A signature reuse flaw allowed attackers to turn a ~3,110 NIGHT authorization into 203 million+ NIGHT — a 65,000x inflation effect.
- NIGHT token fell more than 30% to a record low near $0.016 after the stolen tokens were dumped on decentralized exchanges.
- The Midnight Foundation confirmed its core network, validators, and consensus were unaffected — the breach was isolated to the bridge.
- Wanchain has taken the bridge offline and is preparing a full technical post-mortem.
A major crypto bridge exploit hit the Wanchain-operated Cardano-to-BNB Chain bridge on July 21, 2026. Attackers drained roughly 515 million NIGHT tokens, valued at around $13 million, from the bridge treasury.
Wanchain @wanchain_org Cardano bridge was reportedly being attacked, with ~515M $NIGHT drained from the bridge Treasury.
Our initial investigation suggests that the root cause seems to be a non-injective signed-message encoding in the TreasuryCheck validator. The signed message… https://t.co/bnWEnw3Dxc pic.twitter.com/PQFAN6lRn9
— BlockSec Phalcon (@Phalcon_xyz) July 21, 2026
The attack sent NIGHT down more than 30% within 24 hours. CoinGecko data showed the token trading near $0.0186, close to a record low.

Wanchain took the bridge offline shortly after the breach was confirmed. The team said it is preparing a detailed update and technical post-mortem.
How the Attack Worked
Blockchain security firm BlockSec Phalcon identified a flaw in the TreasuryCheck validator used by the Wanchain bridge.
The bridge built its signed messages by raw concatenating 14 variable-length fields with no delimiters or length prefixes. This allowed different combinations of field values to produce the same byte string and hash.
That flaw enabled a signature reuse attack. The attacker reused a legitimate signature that only authorized around 3,110 NIGHT to instead extract over 203 million NIGHT in a single transaction — roughly a 65,000x inflation effect.
The stolen tokens were then dumped on decentralized exchanges, triggering the sharp price drop.
BlockSec noted the contract already contained Cardano’s SerialiseData function but the bridge did not use it when building the signature hash. Using it would likely have prevented the attack.
Midnight Network Was Not Compromised
The Midnight Foundation was quick to separate itself from the incident. It confirmed the exploit was fully isolated to Wanchain’s third-party bridge infrastructure.
“The incident is isolated to the Wanchain Cardano–BNB bridge and does not involve the Midnight Network itself,” the foundation said.
Midnight’s protocol, validators, consensus system, and core infrastructure continued to operate normally throughout the incident.
The breach involved tokens held in the bridge treasury to support cross-chain transfers — not a change to NIGHT’s total supply, which stands at 24 billion tokens. Around 515 million, or roughly 2% of total supply, was affected.
Midnight launched its mainnet in March 2026. It operates as a privacy-focused Cardano partner chain using a dual-token model built around NIGHT and DUST.
The NIGHT token had risen more than 20% around the mainnet launch. The bridge exploit has reversed a portion of those gains.
A Recurring 2026 Pattern
The Wanchain incident is part of a wider pattern of bridge exploits in 2026. Humanity Protocol suffered a $31 million exploit after attackers gained access to multisig wallet keys through a hacked employee laptop. Gnosis Pay confirmed a $1.8 million attack affecting over 5,000 wallets, though it refunded all affected users in full.
Wanchain had operated across dozens of blockchains for over eight years without a major incident before this breach.
The next key developments to watch are Wanchain’s full post-mortem, any compensation plans, and whether NIGHT price and on-chain activity stabilize in the coming days.







