Wanchain’s Cardano-BNB Bridge, an inter-chain protocol that allows the transfer of assets between Cardano (ADA) and other blockchain networks, has allegedly been compromised.
This opened the doors for attackers to drain up to 515 million NIGHT tokens, worth $9 million, from the bridge’s treasury.
According to the investigation, this exploit was caused by a cryptographic vulnerability in the bridge’s TreasuryCheck validator, called non-injective signed message encoding.
Multiple withdrawals resulted in a loss of NIGHT 515 million
For context, each withdrawal request in a secure system is expected to generate a separate message. This is to ensure that the validator’s digital signature can only authorize the transaction in question.
However, this vulnerability was possible due to multiple retraction requests to create the same encrypted message.
As a result, the illicit actor was able to secure the ability to authorize fraudulent withdrawals without accessing the validator’s private key. This was done by reusing a legitimate signature from a legitimate transaction.
The criminal also laundered the stolen NIGHT tokens to ADA. Cardano network.
Steps taken and their impact on GECE
Wanchain has since shut down the Cardano-BNB Bridge and launched an investigation. They even confirmed that the incident was limited to the bridge and did not affect Midnight’s network or Cardano’s core blockchain.


There is an increase in abuses, but hope remains
In fact, in the past week the crypto space has witnessed many exploits in which the criminal took advantage of an apparent flaw in a decentralized protocol. This included Allbridge Core, a cross-chain bridge exploit. $1.65 million loss.
Later, a permanent decentralized exchange called Ostium on Arbitrum became the target of an oracle exploit, resulting in 18 million dollars of damage. Finally, an approved malicious management proposal resulted in an exploit like this: Cost the BONK ecosystem approximately $20 million.
However, despite the increase in attack frequency, DeFiLlama noted that overall losses fell rapidly to $1 billion by July 2026, compared to $2.135 billion seen in the same period in 2025.


Final Summary
- A cross-chain protocol exploit resulted in the loss of 515 million NIGHT tokens worth $9 million.
- By reusing a legitimate signature from a legitimate transaction, the abuser gained access to authorize fraudulent withdrawals.





