Jul 28, 2026 · 8:26 AM
Subscribe
Home Crypto

A missing separator in Wanchain's bridge code turned a $150 transaction into a $13 million theft

A missing separator in Wanchain's bridge code turned a $150 transaction into a $13 million theft

Ron Patel
· 4 min read · 527 reads
A missing separator in Wanchain's bridge code turned a $150 transaction into a $13 million theft

Wanchain's bridge failed at the place users rarely see: the message format. A missing separator let one valid withdrawal signature become a roughly $13 million NIGHT drain.

The technical detail is almost too absurd to believe. Wanchain's Cardano-BNB Chain bridge validator built signed messages by joining 14 variable-length fields with no separators and no length markers. One legitimate signature for roughly 3,110 NIGHT on BNB Chain could be reused for a Cardano withdrawal of 203,001,692 NIGHT instead. Over 65,000 times the intended amount. That is not a small implementation mistake. It is the kind of bug that turns an authorization check into an open door.

According to BlockSec Phalcon's early analysis, the attack hit the TreasuryCheck validator and drained about 515 million NIGHT from the Cardano-side bridge reserve. CryptoTimes' forensic account put the withdrawal window between 14:46 and 14:55 UTC on July 20, 2026. Four transactions did the work. Depending on the price used, public estimates put the loss between roughly $9 million and $13 million.

NIGHT is the native token of Midnight, the privacy-focused project in the Cardano ecosystem. The Midnight Foundation said on July 21 that the incident was isolated to Wanchain's Cardano-BNB bridge and that Midnight's protocol, validator network, consensus and core infrastructure kept operating normally. That distinction is important for holders, but it doesn't make the market reaction irrational. BeInCrypto reported that NIGHT fell to a record low of $0.01524 after the exploit, while CoinDesk reported a near 19% rebound after the selloff as Charles Hoskinson pushed for a broader bridge overhaul.

The bridge was the weak link

Charles Hoskinson, Cardano's founder, did not treat this as a one-off mistake. CoinDesk reported that he blamed legacy third-party bridge architecture and argued for zero-knowledge systems that replace bridge operators and multisigs with cryptographic proofs. He also connected the problem to AI-driven exploit discovery, saying software is now under heavier attack as tools make vulnerability hunting faster.

Here is the thing. Hoskinson has an obvious incentive to point toward Midnight's zero-knowledge design, but the Wanchain exploit gives him a real example to stand on. If you use a bridge, you are trusting more than two chains. You are trusting message formats, validator scripts, off-chain operators, signing flows and whatever assumptions sit between them. Most users never read that layer. Attackers do.

Wanchain said it took the affected bridge offline while it investigated, according to BSCN's account of the incident. The Midnight Foundation also pointed to measures taken by exchanges and ecosystem partners, and separate market reports said platforms including KuCoin, Kraken, Binance, Bybit, OKX and MEXC moved to freeze, restrict or monitor affected NIGHT flows. That is useful containment after the fact. Frankly, it is not the same as prevention.

Bridges keep proving the same point

Cross-chain bridges have been crypto's most reliable source of large losses for years. Ronin lost about $625 million in 2022. Wormhole lost $320 million the same year. Nomad lost roughly $190 million shortly after. Those incidents were not identical, but they all sat around the same basic problem: assets are locked in one place and represented somewhere else, so some system has to decide whether a transfer is valid. Trust is the attack surface.

The Wanchain bug has a precise name: non-injective encoding. Two different sets of inputs can produce the same encoded output. In this case, raw concatenation of variable-length fields let one signed byte string stand for a different transaction than the one originally approved. The code was not magic. It was ambiguous. Separator-free message construction is a known security smell because field boundaries stop being facts and start becoming guesses.

That is what stings. This was not an exotic break of Cardano, Midnight, or public-key cryptography. It was a bridge validator interpreting a correctly produced signature in a way that let an attacker change the economic meaning of the transaction. When infrastructure handles hundreds of millions of tokens, that is enough.

A full zero-knowledge bridge migration will not happen across the industry next week. ZK systems are harder to build, harder to audit and harder to integrate with chains that were not designed around them. But after Wanchain, the burden has shifted. Bridge teams cannot keep asking users to trust multisigs, signing services and custom message encodings as if the risk is theoretical. The bridge is still the bridge. If it fails, your token price and your liquidity learn the difference before the post-mortem is even written.

Also read: The ETH/BTC ratio just broke a year-long downtrend and Tom Lee says crypto rotation has begunBitMart shuts down nine years after launch with its CEO fired two days before the announcementThailand's SEC charges Bitkub and two former directors over five-year cover-up of a $50 million hack

TOPICS
Ron Patel covers cryptocurrency markets, blockchain developments, and digital asset news for Startup Fortune. With a background in financial journalism and over eight years tracking crypto markets through multiple cycles, Ron brings analytical perspective to Bitcoin, Ethereum, and emerging token ecosystems.
Related Articles
More posts →
Loading next article…
You're all caught up