← Wanchain-Cardano Bridge NIGHT Token Exploit (July 2026)1 decision on this page
Audit log
Every state-changing event for Wanchain-Cardano Bridge NIGHT Token Exploit (July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-28 17:16:01ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
AcUvnWV8D1Lj…YGywP73usha256 → base58
verifying row…canonical bytes (21261 B) ▸
{"actor":"system:backfill","investigation_id":"210a0f6a-9ef4-461b-9083-03e89ed7e0c7","kind":"publish","page_slug":"wanchain-cardano-bridge-night-token-exploit-july-2026","published_at":"2026-07-28T17:16:01.438Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Wanchain-Cardano Bridge NIGHT Token Exploit (July 2026)","sections":[{"content":"The exploit occurred between approximately 14:46 and 14:55 UTC on July 20, 2026, with public reporting concentrating on July 21, 2026. Attackers executed four sequential transactions over roughly eight to nine minutes, draining the bridge's Cardano-side lock address. The total amount stolen was approximately 515.2 million NIGHT tokens—the native token of the Midnight Network, a privacy-focused sidechain built on Cardano. At prevailing market prices, the haul was valued at between $9 million and $13 million depending on the price reference used; various outlets cite $9 million (crypto.news), $10 million (CryptoTimes), and $13 million (CoinGape, TokenPost, BeInCrypto). Wanchain suspended the bridge immediately upon detecting the breach. As of late July 2026, no compensation plan had been formally announced and the bridge remained offline.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Wanchain Cardano Bridge Exploited, Hackers Stole $10M in NIGHT Tokens — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/21/wanchain-cardano-bridge-exploited-hackers-stole-10m-in-night-tokens/"},{"credibility":2,"name":"Breaking: Wanchain Cardano Bridge Breached in $13M Hack, 515M NIGHT Tokens Drained — CoinGape","type":"news_article","url":"https://coingape.com/wanchain-cardano-bridge-breached-in-13m-hack-515m-night-tokens-drained/"},{"credibility":2,"name":"Wanchain Cardano bridge exploit drains 515M NIGHT worth $9M — crypto.news","type":"news_article","url":"https://crypto.news/wanchain-cardano-bridge-exploit-drains-515m-night-worth-9m/"},{"credibility":2,"name":"Wanchain Bridge Hack Drains $13M in NIGHT Tokens, Cardano Midnight Network Remains Secure — TokenPost","type":"news_article","url":"https://www.tokenpost.com/news/investing/22221"}]},{"content":"Security firm BlockSec identified the root cause as a non-injective signed-message encoding flaw in the bridge's TreasuryCheck validator. The validator constructed signed messages by raw-concatenating 14 variable-length redeemer fields using an AppendByteString operation, without separators, length prefixes, or type markers between fields. This rendered the encoding non-injective: distinct transaction data structures could produce identical byte-level representations, and therefore identical cryptographic hashes. As a result, a validator signature authorizing one transaction was mathematically valid for a different transaction with the same encoded hash. The attacker exploited this by rearranging field boundaries to construct a Cardano withdrawal instruction whose encoded form was byte-identical to a previously signed, legitimate BNB Chain authorization for approximately 3,110 NIGHT. By replaying that signature, the attacker extracted 203,001,692 NIGHT in the largest single transaction—a 65,000-fold amplification of the authorized amount. Three additional transactions extracted further reserves. The bridge's reserve was depleted by approximately 97.8%, falling from roughly 527 million to approximately 12 million NIGHT remaining. Cardano's Plutus environment provides a SerialiseData function capable of unambiguous encoding, but it was not utilized during signature hash construction. Security analysts recommended switching to canonical structured encoding, implementing domain separation, adding explicit chain and contract identifiers per authorization, enforcing replay protection via consumed-transaction marking, and conducting invariant testing to ensure no two distinct instructions hash identically.","heading":"Technical Vulnerability: Non-Injective Signed-Message Encoding","severity":"critical","sources":[{"credibility":2,"name":"Inside Wanchain's $10M NIGHT Bridge Exploit — CryptoTimes (technical analysis)","type":"research","url":"https://www.cryptotimes.io/insights/wanchain-night-bridge-exploit-signature-flaw/"},{"credibility":2,"name":"$13M Wanchain Bridge Hack Drains 515M NIGHT Tokens via Signature Exploit — Blockonomi","type":"news_article","url":"https://blockonomi.com/13m-wanchain-bridge-hack-drains-515m-night-tokens-via-signature-exploit"}]},{"content":"The attacker routed the stolen NIGHT tokens through a primary Cardano wallet before dispersing them across multiple newly created addresses. Approximately 290–300 million NIGHT were liquidated through decentralized exchange swaps and DeFi protocols on Cardano. An additional approximately 68.27 million NIGHT were deposited into the Liqwid lending protocol as collateral, suggesting the attacker may have been attempting to borrow other assets against the stolen tokens rather than immediately selling the entire position. Coordinated responses from major centralized exchanges—reportedly including Binance, Kraken, KuCoin, Bybit, OKX, Gate, and MEXC—involved freezing accounts and restricting movement of suspected stolen assets. Specific attacker wallet addresses have not been publicly confirmed in verifiable sources reviewed for this investigation. No attacker identity has been disclosed.","heading":"Attacker Behavior and Fund Disposition","severity":"critical","sources":[{"credibility":2,"name":"Inside Wanchain's $10M NIGHT Bridge Exploit — CryptoTimes (technical analysis)","type":"research","url":"https://www.cryptotimes.io/insights/wanchain-night-bridge-exploit-signature-flaw/"},{"credibility":2,"name":"515M NIGHT bridge exploit rocks Cardano but ADA jumps 8% anyway — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/515m-night-bridge-exploit-rocks-cardano-but-ada-jumps-nearly-8-anyway-after-landmark-hard-fork/"}]},{"content":"The NIGHT token fell sharply following the exploit, reaching an all-time low in the range of $0.015–$0.016 intraday on July 21, 2026, representing a decline of 28–43% depending on the reference price. The stolen 515 million NIGHT represented approximately 2% of the project's estimated 24 billion total token supply, but the concentrated sell pressure on decentralized exchanges amplified the price impact. Within 24 hours, NIGHT had partially recovered, posting a rebound of approximately 19–35% from session lows, with some sources citing recovery to approximately $0.022. CoinDesk noted the 19% rebound occurring by July 22, 2026. Despite the exploit, ADA (Cardano's native token) rose approximately 8% and approached $0.20 during the same period, as markets appeared to distinguish between the bridge infrastructure failure and the underlying blockchain's health. The divergence was partly attributed to Cardano's execution of the van Rossem hard fork (protocol version 11) three days prior to the exploit, which expanded Plutus smart-contract functionality.","heading":"Market Impact and Price Action","severity":"high","sources":[{"credibility":1,"name":"Midnight's NIGHT token rebounds 19% after Wanchain bridge hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/22/midnight-token-rebounds-after-wanchain-bridge-hack-hoskinson-calls-for-industry-overhaul"},{"credibility":2,"name":"Wanchain Bridge Breach Sends Midnight Token to All-Time Low — BeInCrypto","type":"news_article","url":"https://beincrypto.com/midnight-night-wanchain-bridge-exploit/"},{"credibility":2,"name":"515M NIGHT bridge exploit rocks Cardano but ADA jumps 8% anyway — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/515m-night-bridge-exploit-rocks-cardano-but-ada-jumps-nearly-8-anyway-after-landmark-hard-fork/"},{"credibility":2,"name":"NIGHT Token Rebounds Sharply After $10M Wanchain Bridge Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/night-token-rebounds-sharply-after-10m-wanchain-bridge-exploit/"}]},{"content":"The Midnight Foundation issued a public statement confirming that the breach was confined to Wanchain's third-party bridge infrastructure and did not disrupt Midnight's protocol, validator network, consensus system, or core infrastructure. The statement read in part: \"This incident does not reflect any vulnerability in the underlying Midnight blockchain.\" The foundation emphasized that NIGHT's smart contract continued functioning normally on Cardano, and that the Midnight Network's validators and consensus mechanism remained uncompromised. Cardano founder Charles Hoskinson commented publicly on July 22, 2026, describing the incident as consistent with systemic bridge risk across the industry. Hoskinson stated: \"Bridges are the most vulnerable of all of these attacks in the cryptocurrency space,\" and analogized systemic risk by noting that partial resistance to an attack vector does not guarantee immunity under sufficient exposure. He advocated for replacing legacy bridge architectures with cryptographic proof-based systems, specifically citing recursive zero-knowledge proofs, trusted execution environments, and multisignature controls. He also referenced future development of identity tools such as Midnight Passport as a basis for insurance products covering security failures. Hoskinson separately stated: \"We have huge things coming for Midnight,\" reaffirming confidence in the project's longer-term trajectory.","heading":"Midnight Foundation and Cardano Network Response","severity":"medium","sources":[{"credibility":1,"name":"Midnight's NIGHT token rebounds 19% after Wanchain bridge hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/22/midnight-token-rebounds-after-wanchain-bridge-hack-hoskinson-calls-for-industry-overhaul"},{"credibility":2,"name":"Cardano Founder Says 'We Have Huge Things Coming for Midnight,' Reaffirms NIGHT Strength After Wanchain Bridge Exploit — TheCryptoBasic","type":"news_article","url":"https://thecryptobasic.com/2026/07/22/cardano-founder-says-we-have-huge-things-coming-for-midnight-reaffirms-night-strength-after-wanchain-bridge-exploit/"},{"credibility":2,"name":"515M NIGHT bridge exploit rocks Cardano — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/515m-night-bridge-exploit-rocks-cardano-but-ada-jumps-nearly-8-anyway-after-landmark-hard-fork/"}]},{"content":"Wanchain took the Cardano-to-BNB Chain bridge offline immediately upon detecting the breach and stated publicly: \"We are aware of an incident affecting the Cardano BNB Chain bridge,\" committing to \"full transparency\" once its investigation concluded. Wanchain CEO Temujin Louie had not issued a detailed personal public statement as of July 22, 2026; the company was described as \"acting first and explaining later.\" Louie, who holds a degree from the London School of Economics, was appointed CEO in February 2024, succeeding Wanchain founder Jack Lu who moved to an advisory role. Wanchain launched in 2017 as one of the earliest cross-chain interoperability projects and had operated bridges across dozens of blockchains for approximately nine years without a previously documented major security incident prior to this exploit. As of late July 2026, no formal post-mortem had been published and no compensation plan for affected users had been announced. The bridge remained suspended.","heading":"Wanchain's Response and Leadership","severity":"high","sources":[{"credibility":2,"name":"Who Is Temujin Louie? Wanchain CEO and the NIGHT Bridge Hack — Phemex","type":"news_article","url":"https://phemex.com/academy/who-is-temujin-louie-wanchain-ceo"},{"credibility":2,"name":"Wanchain Cardano Bridge Exploited, Hackers Stole $10M in NIGHT Tokens — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/21/wanchain-cardano-bridge-exploited-hackers-stole-10m-in-night-tokens/"},{"credibility":2,"name":"Wanchain Bridge Hack Drains $13M in NIGHT Tokens — TokenPost","type":"news_article","url":"https://www.tokenpost.com/news/investing/22221"}]},{"content":"The Wanchain-Cardano bridge exploit occurred during a broader period of elevated crypto security incidents. CryptoTimes reported on July 26, 2026 that the industry lost over $47 million across multiple hacks in a single week, with Wanchain, AFX Trade, and Verus among the affected entities. Cross-chain bridge exploits have historically represented a disproportionate share of crypto losses; prior incidents include the Ronin Bridge hack ($624 million, 2022) and the Wormhole bridge exploit ($326 million, 2022). A 2022 Chainalysis estimate held that approximately $2 billion had been stolen through 13 bridge hacks, representing 69% of all cryptocurrency stolen that year. The NIGHT bridge exploit falls within a pattern of bridge vulnerabilities attributed to complex multi-chain coordination requirements, reliance on off-chain validators or multisig schemes, and insufficient encoding rigor in signed-message construction. The Cardano van Rossem hard fork, executed three days before the exploit, was unrelated to the breach.","heading":"Broader Industry Context","severity":"medium","sources":[{"credibility":2,"name":"Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/26/crypto-loses-over-47m-in-a-week-as-afx-trade-wanchain-verus-get-hacked/"},{"credibility":2,"name":"515M NIGHT bridge exploit rocks Cardano but ADA jumps 8% anyway — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/515m-night-bridge-exploit-rocks-cardano-but-ada-jumps-nearly-8-anyway-after-landmark-hard-fork/"}]},{"content":"No regulatory action by the SEC, CFTC, or other governmental body in connection with this exploit has been reported in verifiable sources reviewed for this investigation as of late July 2026. No law enforcement identification of the attacker has been publicly confirmed. Several major centralized exchanges allegedly coordinated to freeze accounts suspected of receiving stolen assets, but no court orders or formal government directives underlying these freezes have been documented in available sources.","heading":"Regulatory and Legal Status","severity":"low","sources":[{"credibility":2,"name":"515M NIGHT bridge exploit rocks Cardano but ADA jumps 8% anyway — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/515m-night-bridge-exploit-rocks-cardano-but-ada-jumps-nearly-8-anyway-after-landmark-hard-fork/"}]}],"sources_used":[{"credibility":1,"name":"Midnight's NIGHT token rebounds 19% after Wanchain bridge hack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/22/midnight-token-rebounds-after-wanchain-bridge-hack-hoskinson-calls-for-industry-overhaul"},{"credibility":2,"name":"Inside Wanchain's $10M NIGHT Bridge Exploit — CryptoTimes","type":"research","url":"https://www.cryptotimes.io/insights/wanchain-night-bridge-exploit-signature-flaw/"},{"credibility":2,"name":"Wanchain Cardano Bridge Exploited, Hackers Stole $10M in NIGHT Tokens — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/21/wanchain-cardano-bridge-exploited-hackers-stole-10m-in-night-tokens/"},{"credibility":2,"name":"NIGHT Token Rebounds Sharply After $10M Wanchain Bridge Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/night-token-rebounds-sharply-after-10m-wanchain-bridge-exploit/"},{"credibility":2,"name":"Breaking: Wanchain Cardano Bridge Breached in $13M Hack, 515M NIGHT Tokens Drained — CoinGape","type":"news_article","url":"https://coingape.com/wanchain-cardano-bridge-breached-in-13m-hack-515m-night-tokens-drained/"},{"credibility":2,"name":"Wanchain Bridge Hack Drains $13M in NIGHT Tokens, Cardano Midnight Network Remains Secure — TokenPost","type":"news_article","url":"https://www.tokenpost.com/news/investing/22221"},{"credibility":2,"name":"$13M Wanchain Bridge Hack Drains 515M NIGHT Tokens via Signature Exploit — Blockonomi","type":"news_article","url":"https://blockonomi.com/13m-wanchain-bridge-hack-drains-515m-night-tokens-via-signature-exploit"},{"credibility":2,"name":"Wanchain Bridge Breach Sends Midnight Token to All-Time Low — BeInCrypto","type":"news_article","url":"https://beincrypto.com/midnight-night-wanchain-bridge-exploit/"},{"credibility":2,"name":"515M NIGHT bridge exploit rocks Cardano but ADA jumps 8% anyway — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/515m-night-bridge-exploit-rocks-cardano-but-ada-jumps-nearly-8-anyway-after-landmark-hard-fork/"},{"credibility":2,"name":"Wanchain Cardano bridge exploit drains 515M NIGHT worth $9M — crypto.news","type":"news_article","url":"https://crypto.news/wanchain-cardano-bridge-exploit-drains-515m-night-worth-9m/"},{"credibility":2,"name":"Who Is Temujin Louie? Wanchain CEO and the NIGHT Bridge Hack — Phemex","type":"news_article","url":"https://phemex.com/academy/who-is-temujin-louie-wanchain-ceo"},{"credibility":2,"name":"Cardano Founder Says 'We Have Huge Things Coming for Midnight' — TheCryptoBasic","type":"news_article","url":"https://thecryptobasic.com/2026/07/22/cardano-founder-says-we-have-huge-things-coming-for-midnight-reaffirms-night-strength-after-wanchain-bridge-exploit/"},{"credibility":2,"name":"Cardano: Midnight Crashes 35% After 515M NIGHT Exploit Rocks Wanchain Bridge — TheCryptoBasic","type":"news_article","url":"https://thecryptobasic.com/2026/07/21/cardano-midnight-crashes-35-after-515m-night-exploit-rocks-wanchain-bridge/"},{"credibility":2,"name":"Cardano News: Midnight Network Faces Exploit by Association, NIGHT Price Crashes 28% — The Coin Republic","type":"news_article","url":"https://www.thecoinrepublic.com/2026/07/21/cardano-news-midnight-network-faces-exploit-by-association-night-price-crashes-28/"},{"credibility":2,"name":"Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/26/crypto-loses-over-47m-in-a-week-as-afx-trade-wanchain-verus-get-hacked/"},{"credibility":2,"name":"Wanchain's Cardano Bridge Hacked: 515M NIGHT Tokens Stolen — Phemex News","type":"news_article","url":"https://phemex.com/news/article/wanchains-cardano-bridge-hacked-515-million-night-tokens-stolen-93993"}],"summary":"On July 20–21, 2026, an attacker exploited a cryptographic signature-reuse vulnerability in the Wanchain-operated cross-chain bridge connecting Cardano and BNB Chain, draining approximately 515 million NIGHT tokens valued between $9 million and $13 million at the time of theft. The vulnerability resided in the bridge's TreasuryCheck validator, which concatenated 14 variable-length transaction fields without delimiters, allowing a legitimate small-value signature to be replayed against a vastly larger withdrawal. The underlying Midnight blockchain and Cardano networks were not compromised; the breach was isolated to Wanchain's third-party bridge infrastructure.","timeline":[{"date":"2026-07-17","event":"Cardano executes the van Rossem hard fork (protocol version 11), expanding Plutus smart-contract functionality — three days before the exploit.","source":"CryptoSlate","source_url":"https://cryptoslate.com/515m-night-bridge-exploit-rocks-cardano-but-ada-jumps-nearly-8-anyway-after-landmark-hard-fork/"},{"date":"2026-07-20","event":"Attacker executes four transactions between approximately 14:46 and 14:55 UTC, draining approximately 515.2 million NIGHT tokens from the Wanchain Cardano-to-BNB Chain bridge treasury in roughly eight to nine minutes. The exploit is attributed to a non-injective signed-message encoding flaw in the TreasuryCheck validator.","source":"CryptoTimes (technical analysis) / Blockonomi","source_url":"https://www.cryptotimes.io/insights/wanchain-night-bridge-exploit-signature-flaw/"},{"date":"2026-07-21","event":"Wanchain publicly acknowledges the breach and takes the Cardano-BNB Chain bridge offline. NIGHT token falls to an all-time low near $0.015–$0.016, a decline of 28–43% intraday. BlockSec's Phalcon monitor issues preliminary analysis. Midnight Foundation confirms Midnight blockchain is unaffected.","source":"CryptoTimes / CoinGape / TokenPost","source_url":"https://www.cryptotimes.io/2026/07/21/wanchain-cardano-bridge-exploited-hackers-stole-10m-in-night-tokens/"},{"date":"2026-07-22","event":"NIGHT token rebounds approximately 19% from session lows. Charles Hoskinson comments publicly, calling for industry-wide shift to zero-knowledge proof-based bridge infrastructure. CoinDesk reports on the rebound and Hoskinson's statements.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/07/22/midnight-token-rebounds-after-wanchain-bridge-hack-hoskinson-calls-for-industry-overhaul"},{"date":"2026-07-26","event":"CryptoTimes reports the industry lost over $47 million across multiple hacks in a single week, citing Wanchain, AFX Trade, and Verus as among the affected projects.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/26/crypto-loses-over-47m-in-a-week-as-afx-trade-wanchain-verus-get-hacked/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 11a14fd9-b007-4847-bdfb-04383413b9fc
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.