A cross-chain bridge operated by Wanchain suffered a major exploit, draining approximately 515 million NIGHT tokens from its Cardano-side treasury. Blockchain security firm BlockSec estimated the stolen assets to be worth around $9–10 million, triggering a sharp sell-off that sent the NIGHT token down more than 30% within 24 hours.
BlockSec’s initial investigation points to a possible signature reuse flaw in the TreasuryCheck validator used by the bridge. The validator reportedly constructs messages for signing by concatenating 14 fields without clear separators, potentially allowing an attacker to rearrange field values while reusing a previously valid signature for a different transaction. The firm noted that the bridge’s contract already contained Cardano’s SerialiseData function, but it was not utilized in the signature hash, which could have prevented the ambiguity.
The Midnight Foundation, which oversees the Midnight privacy-focused chain, quickly issued a statement emphasizing that the incident was isolated to Wanchain’s third-party bridge infrastructure. “The incident does not involve the Midnight Network itself,” the foundation said, confirming that the core protocol, consensus system, and validators remained secure. The exploit affected the bridged NIGHT supply held in the bridge treasury, not the token’s total on-chain supply.
As news spread, NIGHT’s price plummeted. CoinGecko data showed the token trading near $0.0186, a decline of about 31% in 24 hours. The event erased part of the gains NIGHT had made since Midnight’s mainnet launch in March 2026. The bridge had originally opened in December 2025 to facilitate token transfers between Cardano and BNB Chain. While Wanchain has yet to produce a full technical postmortem, the incident revives longstanding concerns over the security of cross-chain bridges, which have been responsible for billions in losses across the DeFi ecosystem.