Overview
- On July 21, on‑chain records show roughly 515.2 million NIGHT left Wanchain’s Cardano bridge in four rapid transfers to a single wallet.
- BlockSec’s preliminary analysis says the bridge’s TreasuryCheck built signed messages by concatenating 14 variable‑length fields without clear boundaries, creating a non‑injective encoding that could let a valid signature be reused to authorize different withdrawals.
- Investigators report the attacker routed large portions of the stolen NIGHT through fresh wallets and sold about 300 million NIGHT on decentralized exchanges, which pushed the token down more than 30%.
- Wanchain has taken the Cardano–BNB bridge offline and said it will publish a technical post‑mortem, while the Midnight Foundation says its core network, validators, and consensus were not compromised.
- The case underscores recurring security limits of third‑party bridges that hold cross‑chain liquidity and raises questions for users about recovery options, potential token freezes, and whether post‑mortems or trace efforts will restore market confidence.