Wanchain Cardano–BNB Chain bridge hack — July 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 21, 2026 |
| Target type | Cross-chain bridge |
| Loss | $10,000,000Published estimates range $9,000,000 to $13,000,000Price at time of incident |
| Method | Signature verification flawNon-injective signed-message encoding in the bridge's TreasuryCheck validator. The message to be signed was built by concatenating fourteen variable-length redeemer fields with no separators or length prefixes, so different field contents could serialise to an identical byte string. That allowed a signature issued for one withdrawal to be replayed for a different one: an authorisation for roughly 3,110 NIGHT on BNB Chain was reused on the Cardano side to release 203,001,692 NIGHT, about 65,000 times the intended amount. |
| Chains | Cardano, BNB Chain |
| Outcome | Unresolved |
What happened
Roughly 515.2 million NIGHT tokens were taken from the Cardano side of the Wanchain-operated bridge linking Cardano and BNB Chain on 20 July 2026, in a window reported as 14:46 to 14:55 UTC. Much of the coverage is dated 21 July, which is when the incident was reported rather than when it happened. Wanchain acknowledged unauthorised withdrawals and took the bridge offline. The Midnight Foundation said the Midnight network, its validators and its consensus were unaffected and that the problem was confined to third-party bridge infrastructure.
BlockSec traced the cause to non-injective message encoding in the bridge's TreasuryCheck validator. The validator built the message it signed by concatenating fourteen variable-length redeemer fields with no separators or length prefixes, so different combinations of field contents could serialise to the same byte string. That let a signature issued for one withdrawal be replayed for a completely different one. A legitimate authorisation for about 3,110 NIGHT on BNB Chain was reused on Cardano to release 203,001,692 NIGHT, roughly 65,000 times the intended amount. BlockSec noted the contract already contained Cardano's SerialiseData function but the bridge did not use it when generating the signature hash. The signature remained cryptographically valid; what changed was the meaning assigned to it.
The dollar figure is unsettled because NIGHT's price moved sharply during and after the exploit. Valuing the tokens near $0.025, the pre-exploit price, gives about $13 million, the figure used by CoinGape. At a price during the sell-off the total is roughly $10 million, the figure used by The Crypto Times; crypto.news used about $0.0186 to reach $9 to $10 million. None of these represent realised proceeds, since selling that quantity into available liquidity would incur heavy slippage. NIGHT fell more than 30 per cent to a record low near $0.016 before recovering part of the drop.
Wanchain offered the attacker a 10 per cent white-hat bounty for returning the remaining 90 per cent, with a deadline of 6 August 2026 at 12:00 UTC and a pledge not to pursue civil claims. It had not published a technical post-mortem.
Sources
- The Crypto TimesSecondary · retrieved 2026-08-01
- CoinGapeSecondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Wanchain Cardano–BNB Chain bridge hack — July 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/wanchain-cardano-bnb-bridgehttps://itokenly.com/hacks/wanchain-cardano-bnb-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.