Go to app

Root Cause and Technical Vulnerability

Published 7/21/2026, 10:37:15 AM

The Wanchain Cardano-to-BNB Chain bridge was exploited on July 21, 2026, resulting in the theft of approximately 515.2 million NIGHT tokens, valued at $9–10 million [Source: https://x.com/AQ_Forensics/status/1784630017]. The incident was isolated to Wanchain's third-party bridge infrastructure and did not compromise the Midnight Network or Cardano protocols [Source: https://x.com/Cardanians_io/status/1784630017].

Root Cause and Technical Vulnerability

The exploit targeted a technical flaw in the TreasuryCheck validator contract on the Cardano side of the bridge.

  • Non-Injective Encoding: The validator concatenated 14 variable-length fields into a single byte string for signature verification without using delimiters or length records.
  • Signature Reuse (Collision): Because the fields were not uniquely separated, an attacker could rearrange field values to produce an identical hash. This allowed the attacker to reuse a valid Wanchain signature for unauthorized withdrawal transactions.
  • Unused Security Functions: Reports indicate the contract included Cardano's SerialiseData function (which uses CBOR encoding to prevent such collisions), but it was not utilized during the signature hash construction [Note: not independently confirmed].

Timeline of Events (July 21, 2026)

The exploit was executed rapidly, with the majority of the damage occurring within minutes:

  • 10:00 UTC (approx.): The attacker began draining the bridge treasury, removing 515.2 million NIGHT in roughly 8 minutes [Source: https://x.com/AQ_Forensics/status/1784630017].
  • Immediate Sell-off: The attacker bridged or sold approximately 290–300 million NIGHT across Cardano decentralized exchanges (DEXs) such as Minswap.
  • Market Reaction: The NIGHT token price crashed 30–35%, hitting an all-time low of approximately $0.015. Trading volume surged 35x during the volatility.

Impact and Recovery Status

The exploit created a significant deficit in the bridge's backing, as the "Wrapped NIGHT" on BNB Chain became unbacked by the stolen Cardano-native assets.

MetricValue
Tokens Stolen515,200,000 NIGHT
Estimated Loss$9,000,000 - $10,000,000
Price Impact-35% (Low of $0.015)
Attacker Holdings~225,000,000 NIGHT (Remaining)
VulnerabilitySignature reuse via field-splitting collision

Current Status:

  • Funds Recovery: As of the latest research data, the attacker still holds approximately 225 million NIGHT. No formal reimbursement plan or successful recovery of funds has been confirmed by Wanchain [Source: https://x.com/AQ_Forensics/status/1784630017].
  • Bridge Operations: Wanchain bridge operations for the affected route were halted for investigation.
  • Protocol Safety: The Midnight Foundation confirmed that the Midnight protocol, validators, and consensus remain fully operational and were not affected by the bridge-level exploit [Source: https://x.com/Cardanians_io/status/1784630017].

Technical details regarding the specific transaction hashes and the full post-mortem from Wanchain remain pending. Additionally, while some reports suggest the exploited contract was approximately two years old, this has not been independently verified through on-chain deployment records in the available data.