This article was first published on The Bit Journal. A reported security breach involving the Wanchain bridge connecting Cardano and BNB Chain has raised fresh concerns over cross-chain infrastructure after approximately 515 million NIGHT tokens were allegedly drained from the bridge’s Cardano-side treasury. The incident caused a significant market reaction, with Midnight’s native token dropping by over 30% in a single day.
Wanchain @wanchain_org Cardano bridge was reportedly being attacked, with ~515M $NIGHT drained from the bridge Treasury.
Our initial investigation suggests that the root cause seems to be a non-injective signed-message encoding in the TreasuryCheck validator. The signed message… https://t.co/bnWEnw3Dxc pic.twitter.com/PQFAN6lRn9
— BlockSec Phalcon (@Phalcon_xyz) July 21, 2026
BlockSec Reveals Possible Wanchain Bridge Flaw

BlockSec, a blockchain security firm, was the first to report the event claiming that the hacker drained hundreds of millions of NIGHT tokens from the bridge via the Wanchain blockchain. Assuming current market valuations, the assets stolen from NIGHT would be worth approximately $9 million to $10 million, with the figure changing according to the volatility in NIGHT’s market price.
The Midnight blockchain itself is not vulnerable to the exploit, according to BlockSec’s preliminary investigation, which suggests that the vulnerability could have been in the TreasuryCheck validator of the Wanchain bridge.
The security company stated that the validator seems to combine several parts of the transaction into one message that needs to be signed, but without clearly delineating each part or logging its length. This might provide opportunities for attackers to reuse valid signatures for unauthorized transactions if they choose to use different transaction data for the same final byte sequence.
Preliminary Findings Highlight Signature Weakness
BlockSec said its analysis is based on the on-chain Plutus V2 smart contract of the Wanchain bridge and suspicious activity that is associated with the exploit. But the investigation is still on-going and the firm stressed that the findings are “preliminary.”
The researchers also pointed out that Cardano’s built-in SerialiseData function was not used during the process of creating signatures. The firm said that if the transaction fields were properly encoded with clear boundaries, this type of ambiguity could have been avoided.
Midnight Foundation Clarifies Bridge Incident

In response to the report, the Midnight Foundation pointed out that the incident was isolated to third-party infrastructure of the Wanchain bridge, and it did not affect the Midnight blockchain.
The group emphasized that the system has been fully functional, with the central system, validators, and protocol remaining normal during the event. It also stated that the losses were due to brided assets being transferred between chains, and not the creation of new NIGHT tokens.
Wanchain Bridge Security Remains Under Scrutiny
In December 2025, Wanchain added the capability of transferring NIGHT between Cardano and BNB Chain via the Wanchain bridge, enabling users to move assets across networks with the help of cross-chain infrastructure. Midnight is a privacy-focused partner chain based on Cardano, which has two tokens: NIGHT and DUST, and launched its mainnet in March 2026.
Significant pools of locked assets and complex verification systems have brought cross-chain bridges into a spotlight, sparking concerns about their security after the incident at the Wanchain bridge. Although BlockSec has outlined a possible technical explanation, Wanchain has yet to publish a complete postmortem detailing the exploit, recovery efforts, or the status of the affected bridged NIGHT tokens.
🚨 Community Update:
We are aware of reports concerning an incident involving the Wanchain Cardano to BNB bridge affecting bridged NIGHT.
Based on the information currently available, this appears to relate to cross-chain bridge operations and not the @MidnightNtwrk itself. We…
— Midnight Foundation (@midnightfdn) July 20, 2026
Conclusion
The Wanchain bridge exploit further highlights the ongoing security challenges in the cross-chain space, as the investigation into the incident continues. Market participants await the release of Wanchain’s full technical report to help them understand how the vulnerability occurred, retrieve the lost funds, and restore trust in the security of the bridge, though Midnight’s blockchain is not affected.
Follow us on Twitter and LinkedIn, and join our Telegram channel to be instantly informed about breaking news!
Summary
- Wanchain bridge exploit drained 515M NIGHT, sending the token down 30%.
- BlockSec linked the attack to a possible TreasuryCheck flaw.
- Midnight Foundation said the blockchain remains secure.
Glossary of Key Terms
Wanchain Bridge: Transfers assets between Cardano and BNB Chain.
Bridge Exploit: A security breach in a blockchain bridge.
NIGHT Token: Midnight’s native token.
Midnight: A privacy-focused Cardano partner chain.
BlockSec: A blockchain security firm.
TreasuryCheck Validator: A bridge transaction validator.
SerialiseData: A Cardano data encoding function.
Frequently Asked Questions about Wanchain Bridge exploit
1. What happened in the Wanchain bridge exploit?
About 515 million NIGHT tokens were reportedly drained from the bridge.
2. Was Midnight affected?
No. The Midnight blockchain remained secure and operational.
3. What caused the exploit?
BlockSec linked it to a possible TreasuryCheck validator flaw.
4. Is the investigation complete?
No. Wanchain’s investigation is still ongoing.
References
Disclaimer
The article is purely informational and it is not a financial, investment, or a trading advice. Cryptocurrencies are extremely risky and volatile. Before investing, the readers are to conduct personal research and seek the advice of a qualified financial expert.

