Wanchain bridge drained for $13M — NIGHT token crashes a third

iEXExchanger
Wanchain bridge drained for $13M — NIGHT token crashes a third

Attackers turned a single signature for 3,000 tokens into authorization to drain 203 million — Wanchain's bridge concatenated data without delimiters. NIGHT, the token of Cardano's privacy network Midnight, took the hit.

A signature for 3,000 tokens turned into a withdrawal of 203 million. That's how attackers slipped past the Wanchain bridge connecting Cardano and BNB Chain on July 21, draining roughly 515 million NIGHT tokens worth about $13 million.

NIGHT is the token of Midnight, a privacy-focused partner chain built for Cardano by its founder Charles Hoskinson to meet growing demand for confidential transactions. The Wanchain bridge moved assets — including the stablecoin RLUSD — between Cardano and BNB Chain, and it's inside that bridge's code where the flaw was hiding.

Security firm BlockSec Phalcon traced the attack down to the byte level. The bridge's TreasuryCheck validator built its signed message by concatenating 14 variable-length fields with no delimiters and no length prefixes. Different combinations of data could collapse into the exact same byte string and hash. A legitimate signature authorizing a modest 3,110 NIGHT got reused to unlock over 203 million tokens — a 65,000x amplification. Cardano's own serialization function, which would have prevented exactly this kind of collision, simply wasn't used when the bridge built its signature hash.

NIGHT's price crashed more than 30%, hitting a record low near $0.016-0.019. The stolen tokens amount to roughly 2% of NIGHT's 24 billion total supply, but represented nearly the entire bridge treasury. Wanchain took the bridge offline and opened an investigation; the Midnight Foundation moved quickly to reassure holders, stressing the breach was isolated to third-party bridge infrastructure and never touched its validators, consensus mechanism or core protocol.

That distinction is technically accurate — Midnight itself wasn't hacked. But bridges keep being the weak link in multichain infrastructure, for a second year running: Humanity Protocol lost $31 million to a bridge-adjacent exploit in June, and the Ostium oracle was drained for $18 million just last week. Attackers increasingly aren't breaking blockchains themselves — they're finding the seam where two systems are supposed to agree on the same data format and quietly don't.

Questions and answers

Frequently asked questions about this article

What exactly was hacked — Cardano itself or Midnight?

Neither directly. The hack hit Wanchain, a third-party bridge that moves tokens between Cardano and BNB Chain. Midnight's own network, validators and consensus were untouched — the flaw was in the bridge's code.

How did hackers turn a 3,000-token signature into a 203 million withdrawal?

The bridge's validator built its signed message by concatenating 14 data fields with no delimiters and no length prefixes. Different data sets could collapse into the same byte string and hash, letting a legitimate small-amount signature be reused to authorize a far larger withdrawal.

What is NIGHT and the Midnight network?

Midnight is a privacy-focused partner blockchain built for Cardano by its founder Charles Hoskinson, designed for confidential transactions and applications. NIGHT is its native token, with a total supply of 24 billion.

Is this the first major bridge hack in 2026?

No. In June, Humanity Protocol lost $31 million to a similar exploit, and just last week the Ostium oracle was drained for $18 million. Bridges and cross-chain infrastructure have been DeFi's top hacker target for a second year running.