Incident case file
Sign in to watchWanchain Cardano–BNB Chain Bridge — Non-injective signature encoding flaw (NIGHT)
2 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: W1 (primary, Cardano): addr1qysj48kpy8qra2g64scvu79n489qrv2uys5ggsrun29v5f5udqxfpr7x0pqfl6khjwv6vm0k8s3spn6h0zfrwszfqgcqeld8kj | W2 (secondary, Cardano): addr1qx7haxyr5qdwcpkvdjmrjnk8wzrsyh7usaajpt3crmted5nkw3n3ner7p6vjudr5urnxywhx0zj5e487w5d3ry4s6nsq2k7aq5 | W3 vault (Cardano): addr1qyx992x3khmvc0leu8qge5gs4yys53eecarkx29cyekqfzscummv9adtkfu3qsssupfzxgv5vldajdnuj8926xa8kn0q3mhtym | Stake key: stake1uxwxsrys3lr8ssylatte8xdxdhmrcgcqeath3y3hgpysyvq7kng6l
Timeline: On July 20, 2026 between 14:46 and 14:55 UTC, an attacker drained 515.2 million NIGHT tokens from the Cardano-side treasury of Wanchain's Cardano-to-BNB Chain bridge in four rapid transactions over approximately 8-9 minutes. The primary exploit transaction (0a4861be5dd1cd0a5ccd7d38855ef8fe233563274c22c27adb4f5980535d2ea1, block 13702781) transferred 203,001,692.164714 NIGHT from the bridge lock address to attacker wallet W1. Three additional transactions transferred 129.6M, 120.4M and 62.1M NIGHT. Root cause (per BlockSec Phalcon, July 21): the bridge's TreasuryCheck Plutus V2 validator constructed signed messages by directly concatenating 14 variable-length redeemer fields without separators or length markers, allowing a legitimate BNB Chain signature authorizing ~3,110 NIGHT to be replayed on Cardano for a 203M NIGHT withdrawal — a ~65,000x amplification via field-boundary ambiguity. NIGHT price crashed 30-43% to a record low near $0.016. Wanchain took the bridge offline and began investigating. The Midnight Foundation issued clarifications on July 20 and 21 confirming the incident was isolated to the third-party Wanchain bridge infrastructure; the Midnight Network, validators, consensus and core infrastructure were fully secure. Approximately 90% of stolen NIGHT was aggressively liquidated via Cardano DEX swaps; W2 used 68.27M NIGHT as Liqwid collateral to borrow and extract ADA.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/07/21/wanchain-cardano-bridge-exploited-hackers-stole-10m-in-night-tokens/
- Articlecryptotimes.iohttps://www.cryptotimes.io/insights/wanchain-night-bridge-exploit-signature-flaw/
- Articlecoingape.comhttps://coingape.com/wanchain-cardano-bridge-breached-in-13m-hack-515m-night-tokens-drained/
- Articlecrypto.newshttps://crypto.news/wanchain-cardano-bridge-exploit-drains-515m-night-worth-9m/
- Articleblockonomi.comhttps://blockonomi.com/13m-wanchain-bridge-hack-drains-515m-night-tokens-via-signature-exploit
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articledefillama.comhttps://defillama.com/hacks
- Articlecardanoscan.iohttps://cardanoscan.io/transaction/0a4861be5dd1cd0a5ccd7d38855ef8fe233563274c22c27adb4f5980535d2ea1
- Articlexcancel.comhttps://xcancel.com/Phalcon_xyz/status/2079443108027421183
- Articlexcancel.comhttps://xcancel.com/midnightfdn/status/2079370237334413522
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)