Wanchain Cardano-BNB Bridge (NIGHT) (2026) — Crypto Hack
ActiveThe Wanchain Cardano-BNB Chain bridge was drained of 515.2M NIGHT tokens (~$9-10M) due to a non-injective signed-message encoding flaw in the TreasuryCheck Plutus V2 validator. A 3,110 NIGHT authorization was replayed as a 203M NIGHT withdrawal (65,000x amplification). NIGHT crashed 30-43%.
Summary
The Wanchain Cardano-BNB Chain bridge was drained of 515.2M NIGHT tokens (~$9-10M) due to a non-injective signed-message encoding flaw in the TreasuryCheck Plutus V2 validator. A 3,110 NIGHT authorization was replayed as a 203M NIGHT withdrawal (65,000x amplification). NIGHT crashed 30-43%.
How It Was Compromised — Bridge via Non-Injective Signature Encoding Flaw
The Wanchain cross-chain bridge connecting Cardano and BNB Chain was exploited on July 20, 2026, resulting in the theft of 515.2 million NIGHT tokens worth approximately $9-10 million. The root cause was a non-injective signed-message encoding flaw in the TreasuryCheck Plutus V2 validator. The validator concatenated 14 variable-length fields without separators or length markers, allowing signature reuse. A legitimate authorization for 3,110 NIGHT was replayed as a withdrawal of 203 million NIGHT, representing a 65,000x amplification of the original authorized amount. The NIGHT token crashed 30-43% following the exploit. The incident highlighted the critical importance of injective encoding in cryptographic signature validation, particularly in cross-chain bridge implementations.
Fund Flow & Laundering Analysis
Stolen NIGHT tokens were swapped across the Cardano and BNB Chain networks, with the attacker exploiting the cross-chain bridge's own infrastructure to move funds before the vulnerability could be patched.