What to know:
- Wanchain bridge exploit drained 515M NIGHT and sent the token down sharply in 24 hours.
- BlockSec linked the exploit to a possible flaw in the TreasuryCheck validator design.
- Midnight said its blockchain remained secure as Wanchain reviewed the bridge incident.

The Wanchain bridge exploit reportedly drained about 515 million NIGHT tokens from the Cardano-side treasury of Wanchain’s Cardano-to-BNB Chain bridge. Blockchain security firm BlockSec disclosed the incident. The token then fell more than 30% within 24 hours in sharp trading.
In a post on X, BlockSec’s Phalcon said an early review found a possible weakness in the TreasuryCheck validator. The firm stressed that its findings were preliminary. Midnight Foundation said the incident affected third-party bridge infrastructure, not the Midnight blockchain or core systems.
Also Read: Coinbase CEO 2026 Clarifies No Token Endorsements
What BlockSec Found in the TreasuryCheck Validator
According to BlockSec, the Wanchain bridge exploit may involve how TreasuryCheck prepares messages for signing. The validator combines 14 fields of different lengths. It adds no clear separators and does not record each field’s length before signing.
According to BlockSec, the design was susceptible to signature reuse. In other words, an attacker could shuffle field values while preserving the signed message and hence allowing a valid signature to validate another transaction.
The initial assessment was made based on the Plutus V2 source code and the transaction related to the attack. Structured encoding would have clarified the ambiguity, because the well-defined boundaries would ensure that different data sets do not generate one signed message.
Another fact is that the contract includes the SerialiseData function of Cardano. However, the bridge does not seem to use this function for the signature hash. According to BlockSec, having clear boundaries can mitigate the issue.
The support for cross-chain NIGHT was introduced in December 2025. The solution enables users to transfer assets through the infrastructure provided by Wanchain. According to the Cardano ecosystem directory, WanBridge uses threshold signature relays in EVM and non-EVM ecosystems.
Midnight Responds as NIGHT Falls 29%
The Midnight Foundation initially said that it was investigating issues related to bridged NIGHT. Later, the organization stated that the Wanchain bridge attack was related to the infrastructure developed outside the protocol, and the validators and consensus worked normally.
The company claimed that it was working with Wanchain while conducting the investigation. Wanchain had not made a conclusive technical explanation in the available information. Additionally, BlockSec explained that their findings were only preliminary, not definitive.
As of writing, NIGHT reached an intraday high of $0.02689 before dropping to $0.01582. As per the report, it was trading at $0.0174, a drop of 29% within 24 hours. Daily volume rose 825% to $143.42 million as on-chain selling activity increased sharply.
Wanchain bridge exploit resulted in a supply overhang for NIGHT. According to the report, any unsold holdings would continue impacting the token. Further sales would result in downward pressure on its price in the short term.
Why Wanchain Bridge Exploit Volatility Remains
The token managed to recover from its session low; however, any unsold holdings associated with the Wanchain bridge exploit posed a risk to the market.
Any subsequent sale would extend the volatility period while the investigators examine the controls of the bridge and affected tokens.
The Wanchain bridge exploit is currently under the review of Wanchain, BlockSec, and the Midnight Foundation. The findings available so far indicate potential vulnerabilities in the message encoding but not conclusively. As per the foundation, Midnight’s network continued operating.
Also Read: Tether Gold Price Holds Near $4K After Bullish ADGM Recognition





Be the first to comment