On July 21, 2026, an attacker exploited a signature-reuse vulnerability in the Wanchain-operated bridge connecting Cardano and BNB Chain, stealing approximately 515 million NIGHT tokens valued at around $13 million. Following the breach, major exchanges have frozen deposits and withdrawals of the NIGHT token to prevent further losses.
Details of the Exploit and Market Impact
The attacker took advantage of a flaw in the TreasuryCheck validator, which combined 14 variable-length data fields into one message without clear separation, enabling signature reuse. A signature that originally authorized transferring 3,110 NIGHT was reused to move over 203 million NIGHT in a single transaction. This vulnerability led to a massive token drain and pushed the NIGHT price down roughly 30%, hitting a record low near $0.016.
Wanchain promptly took the bridge offline and issued a security notice on X, stating their investigation is ongoing. Exchanges including KuCoin, Kraken, Binance, Bybit, OKX, and MEXC have coordinated with the Midnight Foundation to manage the fallout.
Midnight Foundation Response and Network Status
The Midnight Foundation clarified that its own network, validators, and consensus mechanisms remain unaffected by the breach. The incident is isolated to the bridge's infrastructure, which relays bridged NIGHT tokens between chains. This distinction matters to holders assessing their exposure, as the stolen tokens came from the cross-chain bridge, not the core Midnight blockchain.
Wanchain has operated cross-chain bridges for over eight years without a security incident of this magnitude, highlighting the severity of this exploit. The theft shows risks involved in bridging tokens across ecosystems.
Material is for informational purposes only and does not constitute financial advice.



