Key takeaways
- Approximately 515 million NIGHT tokens worth $13 million were stolen from Wanchain’s Cardano-to-BNB Chain bridge infrastructure on July 21, 2026.
- Exploits took advantage of a critical signature reuse vulnerability, converting an approximately 3,110-night license into over 203 million tokens – representing a 65,000-fold magnification.
- The price of the NIGHT token fell by more than 30%, reaching an all-time low of $0.016 following a mass sale of at-risk assets on DEX platforms.
- The Midnight Foundation verified that the blockchain infrastructure, validation network, and consensus mechanisms remained completely secure – and the vulnerability was limited exclusively to bridge operations.
- Bridge services have been suspended by Wanchain while investigators work on a comprehensive technical analysis report.
On July 21, 2026, a major security breach targeted the Wanchain-operated bridge connecting Cardano to the BNB chain. Malicious actors successfully extracted approximately 515 million NIGHT tokens from the bridge treasury, representing approximately $13 million in market cap.
The market reaction was fast and severe, with NIGHT seeing a price drop of more than 30% the next day. According to CoinGecko tracking data, the token has reached around $0.0186, marking a new historical low point.

After confirming the security incident, Wanchain immediately disabled the bridge function. The development team announced plans to release a comprehensive report on the incident with a full technical disclosure.
Technical collapse of exploitation
Security researchers at BlockSec Phalcon have identified a critical vulnerability within the secureCheck component deployed by Wanchain’s bridge architecture.
The fundamental issue stems from how the bridge is constructed for signed messages. It serialized 14 variable-length data fields directly without incorporating delimiters or length pointers. This design flaw created a scenario where different input combinations could generate identical byte sequences and resulting hash values.
Exploiting this vulnerability, attackers carried out a re-signing attack. They reused an originally valid signature that allowed around 3,110 NIGHT tokens to withdraw over 203 million NIGHT in a single transaction instead – achieving a multiplier effect of around 65,000x.
The hacked tokens were then liquidated across multiple decentralized exchanges, creating intense selling pressure that led to a significant price drop.
BlockSec analysts noted that the smart contract has already been integrated Cardano SerialiseData function, but the bridge implementation fails to utilize it while generating the signature hash. Proper implementation of this functionality could have effectively prevented this attack vector.
The basic infrastructure at midnight is still intact
The Midnight Foundation moved quickly to clarify the scope of the incident. Official statements confirmed that the security settlement was entirely limited to Wanchain’s external bridge solution.
“The incident is limited to the Wanchain Cardano-BNB bridge and is not related to the Midnight Network itself,” the corporation said.
Throughout the entire security event, Midnight’s underlying protocol, validation processes, consensus structure, and underlying infrastructure maintained full operational integrity.
The stolen assets originated from the bridge’s redundant reserves used to facilitate cross-chain transactions – not from any adjustment to the maximum NIGHT supply, which remains fixed at 24 billion tokens. The affected volume of approximately 515 million tokens represents approximately 2% of the total token supply.
Midnight activated its mainnet in March 2026. The network operates as a privacy-oriented partner chain within the Cardano ecosystem, using a dual-token economic model centered around the NIGHT and DUST coins.
After mainnet deployment, NIGHT saw a price increase of over 20%. The bridge compromise wiped out much of these earlier gains.
2026 Growing bridge security crisis
The Wanchain incident represents another chapter in an expanding series of bridge-related security failures throughout 2026. Humanity Protocol suffered a $31 million loss when attackers compromised multi-signature wallet credentials through an infected employee’s device. Gnosis Pay revealed a $1.8 million hack affecting more than 5,000 user wallets, although the platform offered full compensation to all victims.
Before this security breach, Wanchain had maintained cross-chain operations spanning dozens of blockchain networks for more than eight years without suffering a major security incident.
Critical upcoming developments include Wanchain’s detailed post-mortem technical post, potential victim compensation strategies, and whether NIGHT can achieve price stability and restore on-chain activity metrics in the upcoming trading sessions.






