Wanchain's Cardano bridge exploited for 515M NIGHT tokens (~$9M) via signature reuse vulnerability in TreasuryCheck validator; NIGHT crashes 30% to record low.
Security & Exploits ·
A bridge connecting Wanchain and Cardano has suffered a significant exploit, with approximately 515 million NIGHT tokens removed from the treasury. BlockSec's Phalcon identified a potential vulnerability in the TreasuryCheck validator related to non-injective signed-message encoding, which may have permitted signature reuse attacks.
NIGHT serves as the native token of Midnight, a privacy-focused blockchain incubated by Input Output, the developer behind Cardano. The market responded sharply to the breach, with NIGHT declining more than 30% during intraday trading and reaching a record low of approximately $0.016 per token. At that price level, the drained amount represents roughly $9 million in value.
The technical details of how the vulnerability was exploited and the timeline for remediation remain unclear. No statements have been reported from Wanchain, Input Output, or Midnight regarding response measures or fund recovery efforts.