Wanchain's Cardano cross-chain bridge hit by exploit; about 515 million NIGHT stolen
AI Market Summary
BlockSec reports an exploit of Wanchain's Cardano crosschain bridge, with ~515M NIGHT stolen. The suspected root cause is a non-injective message-encoding design (raw concatenation of variable-length fields without delimiters), enabling hash collisions and signature reuse. This is negative for NIGHT liquidity and bridge risk premia, and may briefly widen scrutiny across crosschain infrastructure tied to Cardano routing.
Impact level
● Medium
Affected assets
NIGHT/USDT-7.17%
AI Insight · NIGHT/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ME News reported that on July 21 (UTC+8), BlockSec Phalcon monitoring flagged an attack on Wanchain's Cardano cross-chain bridge, with roughly 515 million NIGHT tokens taken.
Early findings point to a non-injective encoding flaw in the TreasuryCheck validator used to verify signed messages. The signed payload was built by directly concatenating 14 variable-length redeemer fields via an `AppendByteString` fold, without delimiters or length prefixes. As a result, different combinations of field values could map to the same byte string, produce the same hash, and allow a valid signature to be reused. (Source: Foresight News)