Midnight’s NIGHT token surged 19% following a bridge exploit that drained approximately $13 million from Wanchain’s Cardano-BNB infrastructure. The incident highlights persistent vulnerabilities in cross-chain bridges while the core Midnight network remained secure.
🔑 Key Takeaways
- 515 million NIGHT tokens (~$13M) were drained via a flaw in Wanchain’s TreasuryCheck validator
- The token crashed 32% to 43%, hitting an all-time low of $0.01524 before recovering 19%
- Midnight Foundation confirms the mainnet protocol, validators, and consensus remain secure
- Charles Hoskinson calls for industry-wide security overhaul, advocating zero-knowledge systems
- Cross-chain bridge hacks have collectively caused over $1.5 billion in losses since 2022
Technical Exploit Breakdown
The hack occurred between 14:46 and 14:55 UTC, according to on-chain analyst known as Paul. Attackers exploited a signed message coding flaw in Wanchain bridge’s TreasuryCheck validator, detailed blockchain security firm BlockSec Phalcon.

The attack mechanism relied on a vulnerability in how the bridge created signed messages. The system concatenated 14 variable-length redeemer fields without delimiters or length identifiers, allowing attackers to reuse a legitimate signature to authorize significantly larger fraudulent withdrawals.
| Parameter | Value |
|---|---|
| Initially approved amount | ~3,110 NIGHT |
| Fraudulently withdrawn amount | 203 million NIGHT |
| Amplification factor | ~65,000x |
| NIGHT reserves before attack | 527 million |
| NIGHT reserves after attack | 12 million |
| Percentage lost | ~97% |
In a single transaction, the attacker transformed an approved transfer of approximately 3,110 NIGHT into a withdrawal exceeding 203 million NIGHT. Only NIGHT tokens left the smart contract; other bridged assets remained intact, the analyst noted.
« The bridge created signed messages by concatenating 14 variable-length redeemer fields without separators or length identifiers. This design allowed additional data to be injected into a valid signature. »
BlockSec Phalcon, technical analysis
Price Impact and Market Dynamics
Following the security incident, the NIGHT token collapsed 32% to 43%, reaching a new all-time low of $0.01524 according to multiple sources, with some placing the bottom at $0.015 or $0.016.
The attacker routed funds through newly created wallets and sold them on Cardano-based decentralized platforms. Approximately 290 million NIGHT were dumped on DEXs, triggering widespread panic selling. Market capitalization plunged 27% to $324 million, while trading volume exploded 829% to $131 million.
| Indicator | Change/Value |
|---|---|
| Price crash | -32% to -43% |
| All-time low | $0.01524 |
| 24h post-crisis rebound | +19% (~$0.022) |
| Market capitalization | $324M (-27%) |
| Trading volume | $131M (+829%) |
| 24h spot volume | $624M |
| Futures outflows | $67.4M |
| RSI (oversold territory) | 17 |
Traders quickly closed positions to avoid further losses, as indicated by futures outflows totaling $67.4 million. The token’s relative strength index fell to extremely oversold territory at 17, signaling intense selling pressure and a high probability of prolonged weakness.
« Magically, they forget to mention the rebound. »
Charles Hoskinson, Cardano founder, post on X
Institutional Responses and Foundation Position
Wanchain immediately took the bridge offline and opened an investigation to determine the exact circumstances of the incident. Meanwhile, the Midnight Foundation confirmed the incident was isolated to the third-party bridge infrastructure and had not impacted Midnight’s main network.
« Midnight’s protocol, validator network, consensus mechanism, and core infrastructure remain secure and continue to operate normally. This was a bridge layer incident only, and total token supply remains unchanged. »
Midnight Foundation, official statement
The foundation clarified that wrapped NIGHT on BNB Chain was no longer backed, with wrapped NIGHT tokens now largely unbacked. Investors are now awaiting Wanchain’s post-mortem report, potential compensation plans, and the bridge restoration timeline.
Hoskinson’s Call for Industry Overhaul
Charles Hoskinson, Cardano’s principal developer whose ecosystem Midnight is closely tied to, used the incident to call for a fundamental overhaul of the crypto sector’s security. In an interview with CoinDesk, he described the hack as a « Monday case » while acknowledging its severity in the broader context.
Hoskinson pointed to an increase in Linux kernel vulnerabilities that he attributes to AI-powered exploit discovery. He was direct about the limitations of even well-built systems.
« It’s like being 90% resistant to a deadly disease. If you’re exposed enough, you’ll still end up getting it. »
Charles Hoskinson, CoinDesk interview
Hoskinson blamed the legacy bridge architecture built by a third party and argued that zero-knowledge systems like Midnight represent the long-term solution, replacing trust in bridge operators and multisigs with cryptographic proofs.
« Zero-knowledge systems like Midnight are designed to entirely eliminate this reliance on trust. »
Charles Hoskinson, Cardano principal developer
Industry Context and Precedents
The hack is part of a series of incidents affecting crypto infrastructure in 2026. In July alone, over $59 million in crypto assets were exploited, bringing year-to-date hack totals to approximately $1 billion.
| Incident | Date | Amount Lost |
|---|---|---|
| Wanchain hack (Midnight) | July 21, 2026 | $13 million |
| Allbridge Core | July 2026 | $1.65 million |
| Gnosis Pay (Zodiac) | July 2026 | $1.8 million |
| Humanity Protocol | July 2026 | $31 million |
Cross-chain bridge hacks have been among the most persistent and costly attack vectors in the crypto sector for years. The Ronin, Wormhole, and Nomad attacks collectively caused over $1.5 billion in losses, typically targeting smart contracts or multisig configurations that facilitate token transfers between chains.
Outlook and Scenarios
The incident highlights persistent security risks surrounding cross-chain infrastructure, even as base Layer-1 networks like Cardano remain secure and function normally, according to analysts and the Midnight Foundation. The 19% rebound in the NIGHT token suggests market resilience, but the path back to pre-incident levels remains fraught with uncertainties.
Upcoming catalysts include Wanchain’s post-mortem report publication, decisions regarding potential user compensation, and security measures implemented before any bridge resumption. For the broader sector, the incident reinforces the case for zero-knowledge architectures as an alternative to traditional trust-based bridge models.
Sources
- CoinDesk – Midnight Token Rebounds After Wanchain Bridge Hack
- TokenPost – Midnight NIGHT Token Analysis
- CryptoRank – Midnight NIGHT Wanchain Bridge Exploit
- AMBCrypto – Midnight’s 515M NIGHT Hack Analysis
- Yahoo Finance Germany – Wanchain Bridge Hack Coverage
This article is published for informational and educational purposes. It does not constitute investment advice in any way. Conduct your own research (DYOR) before making any decisions.

