Wanchain Cardano-to-BNB Bridge Exploited as Forged Message Extracts $NIGHT

Wanchain’s cross-chain bridge connecting Cardano and BNB Chain was targeted in a July 21, 2026 incident that allowed an unauthorized withdrawal of $NIGHT tokens from the bridge’s Cardano-side treasury.
Wanchain @wanchain_org Cardano bridge was reportedly being attacked, with ~515M $NIGHT drained from the bridge Treasury.
Our initial investigation suggests that the root cause seems to be a non-injective signed-message encoding in the TreasuryCheck validator. The signed message… https://t.co/bnWEnw3Dxc pic.twitter.com/PQFAN6lRn9
— BlockSec Phalcon (@Phalcon_xyz) July 21, 2026
On-chain forensic tracking by BlockSec’s Phalcon monitor indicated that a forged message triggered the extraction, with researchers tracing the vector to a reused signature linked to a legitimate BSC transaction. Wanchain has suspended the bridge while an internal review proceeds.
The activity occurred across four rapid transactions within an eight-minute window. Phalcon’s analysis identified the underlying vector as a signed-message encoding flaw that enabled the attacker to bypass standard verification checks.
While initial forensic tracking highlighted an extraction of roughly 203 million $NIGHT directly tied to the forged message, secondary on-chain observations placed the total drained balance from the bridge treasury near 515 million $NIGHT. The exact final tally remains under verification, as the available source data does not provide a complete breakdown of how the tokens were routed after the initial extraction.
At a pre-drop trading price near $0.0175, the affected balance carried a notional value of approximately $9 million, though market data during the eight-minute window does not confirm whether the full amount was moved for immediate liquidation.
Wanchain acknowledged the event in a public statement, confirming that withdrawals from the Cardano bridge contract had occurred and that the bridge is currently unavailable while the team conducts a full investigation. Separately, the Midnight Foundation, which oversees the Midnight blockchain where $NIGHT functions as the native governance and execution token, clarified that the breach was isolated to Wanchain’s third-party bridge infrastructure.
The foundation stated that the Midnight Network, including its validators, consensus system and core protocol infrastructure, continued to operate normally. The organization noted it is coordinating with Wanchain as the bridge operator continues its forensic review.
WanBridge relies on threshold-signature relayers to coordinate asset movement between EVM and non-EVM networks. The project had previously promoted an operational history spanning several years without a major security incident.
Bridge architectures frequently require multi-layer message verification and validator coordination, which have historically made them frequent targets for signature manipulation and validator bypass exploits across the broader ecosystem. The precise technical cause of the signature reuse and the current status of the extracted funds remain pending official confirmation. Wanchain has indicated it will release a detailed update upon completion of its investigation.






