Exploit of Wanchain Cardano–BNB Bridge on July 20 Drains About 515M NIGHT Tokens; Midnight Chain Unharmed
Reporting from on-chain investigators, market-data services and a blockchain security firm indicates that a Wanchain bridge route involving Cardano was exploited on July 20, draining about 515 million NIGHT tokens and helping send the token down roughly 30% or more within a day. Early reporting also drew an important distinction: the Midnight blockchain itself was not said to have been compromised, with the apparent failure tied instead to bridge logic.
TheCryptoBasic, citing an on-chain investigator thread, reported that the funds reached the attacker’s wallet in four transfers over roughly eight minutes, between about 14:46 UTC and 14:55 UTC on July 20. The reported transfers were about 203.0 million, 129.6 million, 120.4 million and 62.1 million NIGHT. The same reporting said the attacker then sold a large share of the haul on decentralized exchanges, or crypto trading venues that run on blockchain networks, with roughly 300 million NIGHT sold. That included swaps of about 217.7 million NIGHT for 24.02 million ADA and 87.88 million NIGHT for 1.44 million USDCx, according to the on-chain activity cited by TheCryptoBasic.
Market data from CoinGecko showed the fallout almost immediately. NIGHT fell sharply after the incident, with its 24-hour decline reported in the roughly 27% to 35% range across July 21 coverage, alongside a jump in trading volume. CoinGecko also recorded an all-time low for NIGHT on July 20, 2026, underscoring how quickly the selling pressure hit the token after the bridge drain.
According to reporting summarized by TheCryptoBasic, the Midnight Foundation said the Midnight blockchain itself was not compromised and that the issue appeared isolated to the Wanchain Cardano-to-BNB bridge. That distinction matters because it points to a problem in the infrastructure used to move tokens between chains, rather than a failure of Midnight’s own network.
A preliminary technical explanation came from blockchain security firm BlockSec and was summarized by PANews. BlockSec’s early forensic assessment pointed to what it described as a non-injective encoding flaw in the bridge’s TreasuryCheck verifier. In simple terms, the firm said differently structured inputs could produce the same signed message, potentially allowing an attacker to reuse a valid hash or signature to pass verification. PANews said BlockSec reverse-decompiled Plutus V2 bytecode — smart-contract code used in Cardano’s ecosystem — and recommended explicit CBOR serialization, a stricter way of encoding data, as a safer approach for constructing signed messages. That explanation remains an early diagnosis, not a final confirmed cause.
NIGHT is the native token of Midnight, a Cardano-linked privacy-focused project with a fixed supply of 24 billion tokens and a cross-chain distribution model. Wanchain’s WanBridge supports transfers between Cardano and BNB Chain and had publicly supported NIGHT bridging, making it a key custody point for bridged NIGHT. As in other cross-chain systems, that kind of bridge can become a critical attack surface because it depends on complex message verification while holding tokens meant to move between networks.