515M NIGHT bridge exploit rocks Cardano but ADA jumps 8% anyway after landmark hard fork

A major exploit involving a bridge connected to the Cardano ecosystem sent Midnight’s NIGHT token to an all-time low on July 20 after an attacker drained roughly 515 million tokens from infrastructure operated by Wanchain.

The tokens were removed from a Cardano-side lock address backing NIGHT bridged to BNB Chain, leaving only a fraction of the bridge’s previous reserves.

- Advertisement -

NIGHT fell more than 30% during the fallout and touched a record low near $0.015. At prices around the time of the sell-off, the stolen assets were worth roughly $9 million to $10 million.

Wanchain suspended the affected Cardano-to-BNB Chain bridge and began investigating the incident.

What caused Cardano’s Midnight bridge exploit?

Blockchain security firm BlockSec said its preliminary analysis pointed to a possible problem in the TreasuryCheck validator’s signed-message encoding that could have allowed a previously valid signature to be reused with different transaction data.

However, the firm stressed that the investigation remained preliminary.

The Midnight Foundation said the breach was confined to the third-party bridge infrastructure and did not disrupt Midnight’s protocol, validator network, consensus system or core infrastructure. The NIGHT smart contract operating on Cardano also continued functioning.

Midnight later said Binance, Kraken, KuCoin, Bybit, OKX, Gate and MEXC had joined efforts to limit movement of the stolen assets. Measures included freezing or restricting accounts and addresses associated with the incident, blacklisting attacker-linked wallets and suspending NIGHT deposits and withdrawals where necessary.

The response has narrowed the attacker’s access to major centralized trading venues after hundreds of millions of NIGHT moved out of the bridge treasury.

Cardano founder Charles Hoskinson said organizations across the ecosystem formed a “war room” to monitor the situation as it unfolded, bringing together Midnight, Input Output, Intersect and other groups involved in the response.

Hoskinson said audits would be required to establish “ground truth” around the failure and responsibility for the incident.

Hoskinson says bridge risks remain beyond Cardano’s core defenses

The attack has shifted attention toward a part of the crypto stack that Hoskinson says remains particularly difficult to secure even when the underlying blockchain continues operating normally.

Read More:  7 More Deaths from Measles and Symptoms Nationwide

“Bridges are the most vulnerable of all of these attacks in the cryptocurrency space,” Hoskinson said, arguing that cross-chain systems typically depend on sources of verification or trust outside the networks they connect.

Unlike transactions that remain within a single blockchain, bridges must coordinate activity across separate networks. That can require external relayers, validators, multisignature arrangements, or smart contracts that determine whether assets should be released on the destination chain.

As a result, these platforms have become targets for malicious attackers who have stolen more than $2 billion in crypto from these infrastructures.

Meanwhile, Hoskinson used the incident to defend Cardano’s longstanding emphasis on formal methods, peer review and protocol design, which he said reduces the number of potential attack vectors available to malicious actors.

However, he stopped short of describing those practices as complete protection against attackers.

Instead, Hoskinson compared the approach to being 90% resistant to a deadly disease: the likelihood of harm can be substantially reduced while the possibility of failure remains. He said:

“Being 90% resistant to a deadly disease doesn’t mean you’re immune to a deadly disease. It just means more often than not you’re unlikely to catch it.”

That distinction has become increasingly relevant as the Cardano ecosystem expands beyond the security boundaries of its base network.

Midnight temporarily suspended Glacier Drop redemptions in late June after a separate security incident affected some Cardano wallets associated with SecondFi. The foundation resumed redemptions on July 9 after concluding that its own redemption infrastructure and systems were not exposed.

The Wanchain exploit presents a different vulnerability but again shows how losses involving services built around Cardano can emerge without a failure in Cardano’s consensus protocol.

Read More:  Foreign Investment Confidence Won't Return Unless Fuel Crisis is Resolved: BIDA Chairman

Hoskinson said the answer requires additional layers of protection rather than relying solely on the security properties of an underlying blockchain.

He pointed to future bridge designs incorporating recursive or folded zero-knowledge proofs, which could reduce dependence on external sources of validation.

Those systems could be combined with measures such as trusted execution environments and multisignature controls to create additional barriers against unauthorized transfers.

He also highlighted Midnight Passport, an identity and selective-disclosure system that could allow users to establish ownership of wallets without publicly exposing all of their personal information.

That capability could become useful after hacks in which recovered funds must eventually be returned to legitimate owners. Crypto recovery processes can become difficult when users have lost credentials or when ownership cannot easily be established without sacrificing privacy.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.