- BlockSec linked the exploit to a suspected signature validation flaw in Wanchain’s TreasuryCheck validator.
- Midnight mentioned the incident solely affected Wanchain’s bridge infrastructure, not the Midnight blockchain.
- NIGHT fell over 30% as investigators examined the reported $9 million bridge treasury drain.
A reported exploit concentrating on Wanchain’s Cardano-to-BNB Chain bridge has drained roughly 515 million NIGHT tokens from the bridge treasury. Blockchain safety agency BlockSec mentioned its preliminary investigation factors to a flaw within the bridge’s signature validation course of, whereas the Midnight Basis clarified that the incident didn’t have an effect on the Midnight Community itself.
BlockSec Identifies Attainable Signature Validation Flaw
Blockchain safety agency BlockSec reported on X on July 21 that attackers drained round 515 million NIGHT tokens from Wanchain’s Cardano bridge treasury. The stolen belongings had been valued at roughly $9 million primarily based on prevailing market costs through the reported incident.
In keeping with BlockSec, the suspected vulnerability exists inside the bridge’s TreasuryCheck validator accountable for transaction signature verification. The agency emphasised that its findings stay preliminary whereas technical investigations proceed.
Wanchain @wanchain_org Cardano bridge was reportedly being attacked, with ~515M $NIGHT drained from the bridge Treasury.
Our preliminary investigation means that the basis trigger appears to be a non-injective signed-message encoding within the TreasuryCheck validator. The signed message… https://t.co/bnWEnw3Dxc pic.twitter.com/PQFAN6lRn9
— BlockSec Phalcon (@Phalcon_xyz) July 21, 2026
The validator reportedly constructs signed messages by concatenating fourteen variable-length redeemer fields with out separators or size prefixes.
Consequently, totally different mixtures of subject values can produce equivalent byte strings and matching cryptographic hashes.
That construction might permit attackers to reuse an present legitimate signature for unauthorized transactions underneath particular situations. BlockSec verified its findings after inspecting the on-chain Plutus V2 sensible contract bytecode and decoding the exploit transaction.
Researchers added that utilizing serialized information with specific subject boundaries would have prevented ambiguous message encoding.
Such an strategy would remove alternatives for signature reuse by way of manipulated subject mixtures throughout transaction validation.
Midnight Confirms Core Community Stays Safe
The Midnight Basis responded shortly after experiences of the bridge exploit emerged throughout the cryptocurrency trade. It acknowledged the incident remained remoted to Wanchain’s Cardano-to-BNB bridge infrastructure reasonably than Midnight’s blockchain.
In keeping with the muse, Midnight’s protocol, validator community, consensus mechanism, and core infrastructure proceed working usually with out compromise. It added that the investigation focuses completely on third-party bridge infrastructure supporting cross-chain NIGHT transfers.
The group additionally confirmed it continues working with Wanchain because the bridge operator investigates the reported exploit. Neither celebration has launched a whole technical postmortem or restoration plan on the time of publication.
This distinction stays important as a result of cross-chain bridges function independently from the underlying blockchain securing native digital belongings. Due to this fact, vulnerabilities affecting bridge infrastructure don’t mechanically point out failures inside the related blockchain community.
Bridge Exploit Triggers Sharp NIGHT Value Decline
The reported exploit triggered heavy promoting strain throughout cryptocurrency markets as merchants reacted to the treasury drain. NIGHT declined by greater than 30% inside twenty-four hours following disclosure of the reported assault.
Wanchain launched the Cardano-to-BNB Chain bridge for NIGHT throughout December 2025 to assist cross-chain asset transfers. The bridge locks native tokens whereas issuing equal wrapped belongings to be used throughout supported blockchain networks.
Cross-chain bridges incessantly stay enticing targets as a result of they safe substantial swimming pools of digital belongings supporting wrapped token issuance. Consequently, weaknesses inside bridge validation logic have repeatedly resulted in important cryptocurrency losses throughout a number of blockchain ecosystems.
Investigations into the reported exploit stay ongoing, whereas Wanchain has but to publish an in depth clarification of the vulnerability.
Till then, the total influence, potential restoration efforts, and any further safety measures stay underneath assessment.

