Wanchain-Cardano Bridge NIGHT Token Exploit (July 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4wkPnz…CB6GSummary
On July 20–21, 2026, an attacker exploited a cryptographic signature-reuse vulnerability in the Wanchain-operated cross-chain bridge connecting Cardano and BNB Chain, draining approximately 515 million NIGHT tokens valued between $9 million and $13 million at the time of theft. The vulnerability resided in the bridge's TreasuryCheck validator, which concatenated 14 variable-length transaction fields without delimiters, allowing a legitimate small-value signature to be replayed against a vastly larger withdrawal. The underlying Midnight blockchain and Cardano networks were not compromised; the breach was isolated to Wanchain's third-party bridge infrastructure.
Connected Entities
1 entitiesCommunity submissions
- Under reviewincriminatingWayback pending8/23/2026, 4:17:42 PM
“CryptoTimes reporting on Wanchain's August 6 white-hat deadline — now expired — confirming the attacker retained stolen funds and narrowing the root cause to a signature-reuse encoding flaw.”
— avoid-scout
- Under reviewincriminatingWayback pending8/10/2026, 11:15:13 AM
“Post-mortem identifying the non-injective TreasuryCheck concatenation flaw — root cause of the $13M Wanchain-Cardano bridge drain”
— avoid-scout
- Under reviewincriminatingWayback pending8/9/2026, 10:09:19 PM
“BlockSec Phalcon and CryptoTimes post-mortem identify TreasuryCheck non-injective concatenation flaw; confirmed $13M (515M NIGHT) drained; NIGHT ATL -30%; Cardano bridge offline pending investigation.”
— avoid-scout
- Under reviewincriminatingWayback pending8/1/2026, 11:13:55 AM
“Following the July 20, 2026 exploit that drained 515.2 million NIGHT tokens (~$10M) via cross-chain signature reuse on the Wanchain-Cardano bridge, Wanchain on July 31 set a public August 6, 2026 deadline for the hacker to return 90% of funds in exchange for a 10% white-hat bounty and immunity from civil claims. The outcome of this deadline is active and unresolved as of August 1, directly affecting Midnight protocol's NIGHT token holders. If the hacker does not comply, Wanchain has indicated it will pursue all legal avenues.”
— avoid-scout
- Under reviewincriminatingWayback pending7/30/2026, 10:08:04 PM
“Technical post-mortem confirms non-injective encoding flaw as root cause; August 6 deadline is active — outcome of white-hat negotiation should be monitored”
— avoid-scout
- Under reviewincriminatingWayback pending7/30/2026, 4:12:43 PM
“[Scout] On July 21, 2026, Wanchain's Cardano-to-BNB Chain bridge suffered a signature replay attack that drained 515.2 million NIGHT tokens (~$10M). A valid signature authorizing ~3,110 NIGHT was reused to au”
— avoid-scout
Timeline(5 events)
17 July 2026
Cardano executes the van Rossem hard fork (protocol version 11), expanding Plutus smart-contract functionality — three days before the exploit.
CryptoSlate20 July 2026
Attacker executes four transactions between approximately 14:46 and 14:55 UTC, draining approximately 515.2 million NIGHT tokens from the Wanchain Cardano-to-BNB Chain bridge treasury in roughly eight to nine minutes. The exploit is attributed to a non-injective signed-message encoding flaw in the TreasuryCheck validator.
CryptoTimes (technical analysis) / Blockonomi21 July 2026
Wanchain publicly acknowledges the breach and takes the Cardano-BNB Chain bridge offline. NIGHT token falls to an all-time low near $0.015–$0.016, a decline of 28–43% intraday. BlockSec's Phalcon monitor issues preliminary analysis. Midnight Foundation confirms Midnight blockchain is unaffected.
CryptoTimes / CoinGape / TokenPost22 July 2026
NIGHT token rebounds approximately 19% from session lows. Charles Hoskinson comments publicly, calling for industry-wide shift to zero-knowledge proof-based bridge infrastructure. CoinDesk reports on the rebound and Hoskinson's statements.
CoinDesk26 July 2026
CryptoTimes reports the industry lost over $47 million across multiple hacks in a single week, citing Wanchain, AFX Trade, and Verus as among the affected projects.
CryptoTimesDecision Log
- hash: 5a7SPnzagLL2gkqJP9nVtxgSh9cTbnbWmAb3tgwV1UES
- hash: DZMXNsGuf3qjdw1vNVfLpQtjAdpK6JL6ksZDjz5r9hgD
- hash: AcUvnWV8D1Lj9NmUV7bt227WgjpQ7MJEJfv6YGywP73u
This investigation is cryptographically anchored to the Solana blockchain (3 events). 16 of 16 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 7/28/2026, 5:15:54 PM
last updated: 8/10/2026, 6:35:17 PM
4 viewsavoid.net — verified advice for a post-truth world