In a fresh setback for cross-chain infrastructure, security firm BlockSec’s Phalcon monitor reported on July 21, 2026, that Wanchain’s bridge connecting Cardano to BNB Chain was exploited, resulting in the theft of approximately 515.2 million $NIGHT tokens (approximately $10 million) from the bridge treasury.
The incident, which unfolded in just four rapid transactions over an eight-minute window, highlights persistent vulnerabilities in bridging solutions despite years of industry warnings.
According to initial analysis shared by BlockSec, the root cause appears to be a non-injective signed-message encoding flaw in the TreasuryCheck validator. The signed message was constructed by raw-concatenating 14 variable-length redeemer fields without proper delimiters or length prefixes. This design allowed different field-value combinations to produce identical byte strings, hashes, and therefore valid signature reuses — a classic attack vector that has plagued multiple protocols.
The attacker funneled the stolen tokens into a primary wallet on Cardano before aggressively liquidating roughly 90% of the haul through DEX swaps and DeFi protocols. At prevailing prices around $0.01950 per token, the drained amount equates to roughly $10 million in realized value.
“We are aware of an incident affecting the Cardano BNB Chain bridge, resulting in the withdrawal of NIGHT tokens from the bridge contract on Cardano. The Wanchain Bridge is currently unavailable to users,” said the Wanchain team in a statement. “Please know that this has our full attention. We are committed to full transparency and will share an update as soon as our investigation is complete. We are grateful for your patience and trust.”
NIGHT, the native token of the privacy-focused Midnight blockchain incubated by Input Output (the entity behind Cardano), plunged more than 30–40% intraday, hitting a new all-time low.
Midnight Network quickly issued a statement clarifying that the core Midnight protocol and its Layer-1 remain uncompromised. The breach was confined to Wanchain’s third-party bridging infrastructure. “This incident does not reflect any vulnerability in the underlying Midnight blockchain,” the team emphasized, while acknowledging the short-term market impact from the sudden sell pressure.
This event adds to a long list of bridge exploits that have cost the industry billions since 2017. High-profile cases like Ronin ($624M), Wormhole ($326M), and more recent 2026 incidents underscore how bridges often become the weakest link in DeFi due to complex message verification, validator dependencies, and economic incentives for attackers. Wanchain had previously marketed its multi-year track record of security, making today’s breach particularly notable.
This is a developing story and more information will be added as the event unfolds.
Also read: Polygon Nears Ethereum, Robinhood in Daily DEX Trading Volume
