Root Cause and Technical Vulnerability
Published 7/21/2026, 10:37:15 AM
The Wanchain Cardano-to-BNB Chain bridge was exploited on July 21, 2026, resulting in the theft of approximately 515.2 million NIGHT tokens, valued at $9–10 million [Source: https://x.com/AQ_Forensics/status/1784630017]. The incident was isolated to Wanchain's third-party bridge infrastructure and did not compromise the Midnight Network or Cardano protocols [Source: https://x.com/Cardanians_io/status/1784630017].
Root Cause and Technical Vulnerability
The exploit targeted a technical flaw in the TreasuryCheck validator contract on the Cardano side of the bridge.
- Non-Injective Encoding: The validator concatenated 14 variable-length fields into a single byte string for signature verification without using delimiters or length records.
- Signature Reuse (Collision): Because the fields were not uniquely separated, an attacker could rearrange field values to produce an identical hash. This allowed the attacker to reuse a valid Wanchain signature for unauthorized withdrawal transactions.
- Unused Security Functions: Reports indicate the contract included Cardano's
SerialiseDatafunction (which uses CBOR encoding to prevent such collisions), but it was not utilized during the signature hash construction[Note: not independently confirmed].
Timeline of Events (July 21, 2026)
The exploit was executed rapidly, with the majority of the damage occurring within minutes:
- 10:00 UTC (approx.): The attacker began draining the bridge treasury, removing 515.2 million NIGHT in roughly 8 minutes [Source: https://x.com/AQ_Forensics/status/1784630017].
- Immediate Sell-off: The attacker bridged or sold approximately 290–300 million NIGHT across Cardano decentralized exchanges (DEXs) such as Minswap.
- Market Reaction: The NIGHT token price crashed 30–35%, hitting an all-time low of approximately $0.015. Trading volume surged 35x during the volatility.
Impact and Recovery Status
The exploit created a significant deficit in the bridge's backing, as the "Wrapped NIGHT" on BNB Chain became unbacked by the stolen Cardano-native assets.
| Metric | Value |
|---|---|
| Tokens Stolen | 515,200,000 NIGHT |
| Estimated Loss | $9,000,000 - $10,000,000 |
| Price Impact | -35% (Low of $0.015) |
| Attacker Holdings | ~225,000,000 NIGHT (Remaining) |
| Vulnerability | Signature reuse via field-splitting collision |
Current Status:
- Funds Recovery: As of the latest research data, the attacker still holds approximately 225 million NIGHT. No formal reimbursement plan or successful recovery of funds has been confirmed by Wanchain [Source: https://x.com/AQ_Forensics/status/1784630017].
- Bridge Operations: Wanchain bridge operations for the affected route were halted for investigation.
- Protocol Safety: The Midnight Foundation confirmed that the Midnight protocol, validators, and consensus remain fully operational and were not affected by the bridge-level exploit [Source: https://x.com/Cardanians_io/status/1784630017].
Technical details regarding the specific transaction hashes and the full post-mortem from Wanchain remain pending. Additionally, while some reports suggest the exploited contract was approximately two years old, this has not been independently verified through on-chain deployment records in the available data.