Wanchain Bridge Exploit Drains 515 Million NIGHT Tokens

Signature-Reuse Flaw Leaves Wrapped NIGHT Unbacked and Pressures Token Price
TL;DR
- A signature-encoding flaw allowed fraudulent withdrawals from Wanchain’s Cardano-to-BNB bridge, leaving wrapped NIGHT unbacked.
- NIGHT plunged to an all-time low before rebounding nearly 19% within 24 hours to around $0.022.
- Charles Hoskinson said legacy bridge infrastructure should be replaced with zero-knowledge systems using cryptographic proofs.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
A cryptographic vulnerability in Wanchain’s Cardano-to-BNB cross-chain bridge allowed an attacker to drain 515 million NIGHT tokens worth about $9 million during July 2026. The breach affected the bridge’s custody reserves rather than Midnight’s network or Cardano’s core blockchain, but it left wrapped NIGHT on BNB Chain unbacked and triggered heavy selling in the native token.

The stolen assets had been held in a contract that had operated for about two years and contained the reserves supporting Wanchain-wrapped NIGHT. The attacker removed the contract’s full balance while the supply of wrapped NIGHT on BNB Chain remained unchanged, leaving those tokens without the native NIGHT reserves required to support redemption.
Reused Signature Enabled Fraudulent Withdrawals
The reported vulnerability affected the bridge’s TreasuryCheck validator and involved non-injective signed-message encoding. A secure withdrawal process is intended to generate a unique signed message for each request so that a validator’s signature can authorize only one specific transaction.

Wanchain’s implementation instead allowed multiple withdrawal requests to generate the same encoded message. That weakness enabled the attacker to reuse a valid signature from a legitimate transaction to approve fraudulent withdrawals without gaining access to the validator’s private key.
The exploit therefore involved the bridge’s message-validation logic rather than a compromise of Midnight’s underlying network or Cardano’s base layer. Wanchain later confirmed that the breach was restricted to the bridge and did not affect Midnight’s network or Cardano’s core blockchain.
After withdrawing the reserves, the attacker moved the stolen NIGHT through newly created wallets and transferred the assets toward the Cardano ecosystem. The tokens were then sold through decentralized exchanges, with portions of the proceeds converted into ADA.
About 290 million NIGHT had already been sold after the exploit, representing roughly 56% of the stolen balance. The attacker continued to control the remaining tokens, leaving additional supply available for potential sale.
Wanchain halted the Cardano-BNB bridge and began investigating the fraudulent withdrawals and subsequent movement of funds. Midnight Foundation separately said the Midnight network remained secure and characterized the incident as isolated to cross-chain bridge operations.
We’ve launched the all-new COIN360 Perp DEX, built for traders who move fast!
Trade 130+ assets with up to 100× leverage, enjoy instant order placement and low-slippage swaps, and earn USDC passive yield while climbing the leaderboard. Your trades deserve more than speed — they deserve mastery.
NIGHT Falls to Record Low
NIGHT dropped 32% after the exploit and reached a new all-time low of $0.015 before recovering slightly to $0.019. The token remained below $0.02 following the rebound.
NIGHT’s market capitalization fell 27% to $324 million, while trading volume surged 829% to $131 million. The combination of rising activity, a lower price and a declining market value reflected elevated sell-side pressure after the attacker began disposing of the stolen assets.

Other NIGHT holders also reduced exposure after news of the breach. Spot-market sell volume rose to 624 million NIGHT over 24 hours, showing that selling extended beyond the attacker’s reported transactions.
Derivatives traders also exited positions. Futures outflows reached $67.4 million, while inflows declined to $62.3 million, producing a netflow of negative $5.1 million.
The futures netflow measure fell about 1,000%, indicating that capital leaving the market exceeded incoming funds as traders closed positions and reduced risk.
NIGHT’s Relative Strength Index fell to 17, placing the token in oversold territory. The available technical assessment identified $0.015 as support and said persistent negative sentiment could keep NIGHT below $0.02.
The attacker’s remaining holdings continued to represent a potential source of additional market supply. The supplied information did not specify whether any funds had been recovered or whether the remaining stolen NIGHT had since been sold.
NIGHT Rebounds as Hoskinson Calls for Bridge Overhaul
NIGHT recovered nearly 19% within 24 hours to trade around $0.022 by July 22, partially reversing the decline that followed the Wanchain bridge exploit. Charles Hoskinson criticized coverage that focused on the initial crash without acknowledging the subsequent recovery. “Magically, they forget to mention the rebound,” he wrote on X.

Hoskinson described the incident as a “case of the Mondays” but said it reflected a wider security challenge facing software systems. “All software is under this enormous assault,” he said, attributing rising vulnerability discovery to artificial intelligence. He added: “That’s like being 90% resistant to a deadly disease. If you’re exposed to it enough, eventually you still catch the disease.”
Hoskinson argued that zero-knowledge systems such as Midnight offer a longer-term alternative to legacy bridges. Such systems replace reliance on bridge operators and multisignature arrangements with cryptographic proofs, he said. The Wanchain bridge was developed by a third party and operated separately from Midnight’s underlying network.
Other Exploits Add to 2026 Losses
The Wanchain breach occurred during a broader series of decentralized-finance security incidents involving separate technical and governance failures. More than $59 million in crypto assets was reported exploited during July.
Allbridge Core suffered a separate cross-chain bridge exploit involving $1.65 million. Ostium, a perpetual decentralized exchange on Arbitrum, lost $18 million through an oracle exploit.
The BONK ecosystem lost about $20 million after a malicious governance proposal was approved. The incidents involved different reported weaknesses and were not presented as a coordinated attack or a shared vulnerability.
DeFiLlama placed losses from crypto exploits and scams at $1 billion as of July 2026, compared with $2.135 billion during the same period of 2025. The difference amounted to about $1.135 billion, or roughly 53%.
Attack frequency was described as increasing even though the total dollar value lost remained below the comparable 2025 period.
FAQ
Was Midnight’s network compromised?
No. Midnight Foundation said the incident was isolated to Wanchain’s cross-chain bridge.
Was Cardano’s core blockchain affected?
No. Wanchain said Cardano’s core blockchain was not affected.
How did the attacker approve fake withdrawals?
The attacker reused a legitimate signature because separate requests could produce the same encoded message.
What happened to wrapped NIGHT on BNB Chain?
Its supply remained outstanding after the reserves backing it were drained.
This article has been refined and enhanced by ChatGPT.