Wanchain’s Cardano bridge lost roughly $13 million after an attacker allegedly reused a legitimate cross-chain authorization to inflate a bridged NIGHT transfer by about 65,000x, extracting more than 200 million tokens in a single transaction before swapping a portion into ADA.
Wanchain’s Cardano bridge lost roughly $13 million after an attacker allegedly reused a legitimate cross-chain authorization to inflate a bridged NIGHT transfer by about 65,000x, extracting more than 200 million tokens in a single transaction before swapping a portion into ADA.
What happened in the Wanchain Cardano bridge exploit
Wanchain published a security notice on July 21, 2026 specifically addressing its Cardano to BNB Chain bridge, confirming the cross-chain infrastructure was the focus of the incident, according to the bridge operator’s statement. For related coverage, see Circle President Heath Tarbert Sold $30.8M in CRCL Stock Since 2025 IPO: MSBIntel Data.
The Midnight Foundation said the incident involved the Wanchain Cardano-to-BNB bridge and affected bridged NIGHT, but did not appear to compromise the Midnight network itself, the foundation noted. For related coverage, see SEC and CFTC Open Joint Consultation on Crypto Derivatives Rules.
- What to know: The Wanchain Cardano bridge exploit resulted in a reported loss of roughly $13 million.
- What to know: Security researchers described the attack as a signature-reuse exploit that inflated a bridge authorization by approximately 65,000x.
How the alleged NIGHT signature inflation was described
BlockSec Phalcon traced the redeemer’s uniqueId field back to a legitimate BSC transaction that authorized only about 3,110 NIGHT, then said the same signature was reused on Cardano to extract 203,001,692 NIGHT. The firm characterized the gap as roughly 65,000x inflation caused by field-boundary ambiguity in a raw-concatenated hash. For related coverage, see Grayscale Files for Worldcoin ETF With SEC: What It Means.
This section reflects the reported description of the exploit rather than an independently verified technical reconstruction. BlockSec’s public summary is the clearest available account of the mechanics, and it frames the failure as a message-encoding flaw rather than a compromise of Cardano’s base layer.
BlockSec’s technical thread laid out the authorization mismatch directly, showing how a small approved amount became a nine-figure withdrawal.
We traced the redeemer's `uniqueId` field back to a legitimate BSC TX (`0xe901…f26b`) that authorized only ~3,110 NIGHT. The same signature was reused on Cardano to extract 203,001,692 NIGHT — a ~65,000x inflation via field-boundary ambiguity in the raw-concatenated hash… https://t.co/0aky3N8piM pic.twitter.com/8YguNZWxAe
— BlockSec Phalcon (@Phalcon_xyz) July 21, 2026
Source: @Phalcon_xyz on X
CertiK Alert reported that 203,001,692 NIGHT were falsely minted and then swapped for 2,831,361 ADA, worth about $500,000, on Cardano, providing an on-chain disposal trail for part of the stolen supply.
ADA traded near $0.173 during coverage, up about 3% on the day, giving market context for the value the attacker realized by swapping bridged NIGHT into Cardano’s native asset.
The broader incident totaled approximately 515 million NIGHT, and NIGHT fell more than 30% to about $0.016 after the exploit, TokenPost reported. According to that single secondary summary, no Wanchain postmortem or treasury-level accounting has yet independently confirmed the aggregate figure.
Why the breach matters for cross-chain and altcoin security
The exploit lands on Wanchain’s cross-chain infrastructure connecting Cardano and BNB Chain, the two ecosystems most directly implicated. The core failure was an authorization mismatch, about 3,110 NIGHT approved versus more than 203 million withdrawn, rather than a flaw in either underlying chain.
Bridge exploits remain among the more damaging categories of crypto security incidents because they concentrate value and trust in message-passing logic between chains. The event surfaces amid a cautious market, with the Fear & Greed Index at 25, in Extreme Fear territory.
Scrutiny of cross-chain and asset-backing mechanics has been building across the industry, from efforts to build 1:1 asset-backed tokenized products to sharper regulatory attention on how digital assets move and settle. Recent moves such as the SEC and CFTC’s joint consultation on crypto rules and Pakistan’s new crypto crime unit underscore how operational failures like this one draw wider oversight.
No regulatory filing, enforcement action, or governance vote has been identified in connection with the incident, which currently reads as an operational bridge-security event involving third-party infrastructure. Wanchain has acknowledged the affected bridge but has not yet published a full incident postmortem.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
