Newsroom
22 July, 2026 / News / AI / 634 reads / Tags: midnight, night, cardano, bridge, wanchain

NIGHT plunged to a record low after attackers drained hundreds of millions of tokens from a cross-chain bridge, though core networks remained secure and the project’s leadership signaled strong confidence in its future
An attacker exploited a flaw in Wanchain’s bridge connecting Cardano to BNB Chain, withdrawing approximately 515 million NIGHT tokens. The incident occurred within a short window on July 21, 2026, targeting the Cardano-side lock address that held reserves for wrapped NIGHT assets.
Security researchers identified the root cause as a non-injective message encoding in the bridge’s TreasuryCheck validator. This allowed a legitimate signature authorizing a small transfer of 3,110 NIGHT to be replayed and inflated dramatically, resulting in one transaction moving over 200 million tokens. The vulnerability stemmed from concatenating variable-length fields without proper delimiters, enabling signature reuse.
Wanchain promptly suspended the affected bridge and launched an investigation. The Midnight Foundation confirmed the issue was confined to the third-party bridge infrastructure and did not compromise Midnight’s protocol, validators, consensus mechanism, or Cardano’s underlying blockchain.
The stolen tokens triggered heavy selling pressure. Roughly 290 million NIGHT were dumped on decentralized exchanges, driving the token’s price from around $0.026 to an all-time low near $0.01524. The sharp decline exceeded 30 percent in a matter of hours, with trading volume spiking amid the chaos.
Exchanges including Binance, OKX, Kraken, KuCoin, Bybit, Gate.io, and MEXC responded by freezing deposits and withdrawals of NIGHT and blacklisting attacker-associated addresses. These measures helped contain further liquidation of the stolen funds, estimated at roughly $9 million to $13 million depending on timing.
The Midnight Foundation issued statements emphasizing that Midnight’s own systems continued operating normally throughout the event. They advised the community to rely only on official channels and remain vigilant against phishing attempts.
Cardano founder Charles Hoskinson addressed the situation directly, describing it as Midnight’s first major stress test. He noted the network’s resilience in absorbing the sudden influx of tokens without broader collapse.
Hoskinson further clarified that neither Midnight’s smart contracts nor Cardano’s connected systems were affected. He highlighted the ongoing Glacier Drop distribution, which recently reached a milestone of 1.5 billion NIGHT tokens redeemed, as continuing on schedule.
The exploit underscores persistent risks in cross-chain bridges, which often serve as concentrated points of failure despite connecting otherwise secure blockchains. Industry experts have increasingly pointed to the need for improved designs, such as zero-knowledge proofs and enhanced multisignature systems, to mitigate such vulnerabilities.
This event adds to a series of bridge-related incidents in 2026, though overall DeFi losses have reportedly declined year-over-year. For NIGHT holders, the focus remains on the project’s core privacy-focused technology and upcoming developments outlined by its leadership.
While the token faced immediate selling pressure, buying interest returned as the dust settled, demonstrating some underlying market resilience tied to Midnight’s long-term prospects.









