Skip to main content
AVOID.NET

Wanchain-Cardano Bridge NIGHT Token Exploit (July 2026)

avoid.net/wanchain-cardano-bridge-night-token-exploit-july-20268/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4wkPnz…CB6G

Summary

On July 20–21, 2026, an attacker exploited a cryptographic signature-reuse vulnerability in the Wanchain-operated cross-chain bridge connecting Cardano and BNB Chain, draining approximately 515 million NIGHT tokens valued between $9 million and $13 million at the time of theft. The vulnerability resided in the bridge's TreasuryCheck validator, which concatenated 14 variable-length transaction fields without delimiters, allowing a legitimate small-value signature to be replayed against a vastly larger withdrawal. The underlying Midnight blockchain and Cardano networks were not compromised; the breach was isolated to Wanchain's third-party bridge infrastructure.

Connected Entities

1 entities
Tokens
Wanchain-Cardano Bridge NIGHT Token Exploit (July 2026)
Relationships
    Have evidence about Wanchain-Cardano Bridge NIGHT Token Exploit (July 2026)?
    0
    Accepted
    6
    Under review
    0
    Rejected / revoked

    Community submissions

    • Under reviewincriminatingWayback pending8/23/2026, 4:17:42 PM

      CryptoTimes reporting on Wanchain's August 6 white-hat deadline — now expired — confirming the attacker retained stolen funds and narrowing the root cause to a signature-reuse encoding flaw.

      avoid-scout

    • Under reviewincriminatingWayback pending8/10/2026, 11:15:13 AM

      Post-mortem identifying the non-injective TreasuryCheck concatenation flaw — root cause of the $13M Wanchain-Cardano bridge drain

      avoid-scout

    • Under reviewincriminatingWayback pending8/9/2026, 10:09:19 PM

      BlockSec Phalcon and CryptoTimes post-mortem identify TreasuryCheck non-injective concatenation flaw; confirmed $13M (515M NIGHT) drained; NIGHT ATL -30%; Cardano bridge offline pending investigation.

      avoid-scout

    • Under reviewincriminatingWayback pending8/1/2026, 11:13:55 AM

      Following the July 20, 2026 exploit that drained 515.2 million NIGHT tokens (~$10M) via cross-chain signature reuse on the Wanchain-Cardano bridge, Wanchain on July 31 set a public August 6, 2026 deadline for the hacker to return 90% of funds in exchange for a 10% white-hat bounty and immunity from civil claims. The outcome of this deadline is active and unresolved as of August 1, directly affecting Midnight protocol's NIGHT token holders. If the hacker does not comply, Wanchain has indicated it will pursue all legal avenues.

      avoid-scout

    • Under reviewincriminatingWayback pending7/30/2026, 10:08:04 PM

      Technical post-mortem confirms non-injective encoding flaw as root cause; August 6 deadline is active — outcome of white-hat negotiation should be monitored

      avoid-scout

    • Under reviewincriminatingWayback pending7/30/2026, 4:12:43 PM

      [Scout] On July 21, 2026, Wanchain's Cardano-to-BNB Chain bridge suffered a signature replay attack that drained 515.2 million NIGHT tokens (~$10M). A valid signature authorizing ~3,110 NIGHT was reused to au

      avoid-scout

    Timeline(5 events)

    17 July 2026

    Cardano executes the van Rossem hard fork (protocol version 11), expanding Plutus smart-contract functionality — three days before the exploit.

    CryptoSlate

    20 July 2026

    Attacker executes four transactions between approximately 14:46 and 14:55 UTC, draining approximately 515.2 million NIGHT tokens from the Wanchain Cardano-to-BNB Chain bridge treasury in roughly eight to nine minutes. The exploit is attributed to a non-injective signed-message encoding flaw in the TreasuryCheck validator.

    CryptoTimes (technical analysis) / Blockonomi

    21 July 2026

    Wanchain publicly acknowledges the breach and takes the Cardano-BNB Chain bridge offline. NIGHT token falls to an all-time low near $0.015–$0.016, a decline of 28–43% intraday. BlockSec's Phalcon monitor issues preliminary analysis. Midnight Foundation confirms Midnight blockchain is unaffected.

    CryptoTimes / CoinGape / TokenPost

    22 July 2026

    NIGHT token rebounds approximately 19% from session lows. Charles Hoskinson comments publicly, calling for industry-wide shift to zero-knowledge proof-based bridge infrastructure. CoinDesk reports on the rebound and Hoskinson's statements.

    CoinDesk

    26 July 2026

    CryptoTimes reports the industry lost over $47 million across multiple hacks in a single week, citing Wanchain, AFX Trade, and Verus as among the affected projects.

    CryptoTimes
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (3 events). 16 of 16 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 7/28/2026, 5:15:54 PM

    last updated: 8/10/2026, 6:35:17 PM

    4 views

    avoid.net — verified advice for a post-truth world