A vulnerability in the TreasuryCheck validator of Wanchain’s Cardano-to-BNB Chain bridge allowed an attacker to drain 515.2 million NIGHT tokens between 14:46 and 14:55 UTC on July 20, 2026. Eight minutes. Four transactions. Roughly $13 million in token value. The Midnight Foundation confirmed within hours that the Midnight blockchain itself, its validators, consensus mechanism and core protocol, was completely unaffected. Wanchain confirmed the bridge was a third-party infrastructure layer, not built by Midnight or the Input Output Global team. The NIGHT token crashed 43% to an all-time low of $0.01524 before rebounding 19% within 24 hours to approximately $0.022.
Charles Hoskinson’s response was pointed and strategic. He did not minimize what happened. He used it. The Wanchain bridge, he said, is exactly the kind of legacy infrastructure that Midnight’s zero-knowledge architecture is designed to make obsolete. ‘All software is under this enormous assault,’ he told CoinDesk, citing a surge in Linux kernel vulnerabilities he attributed to AI-powered exploit discovery. ‘That’s like being 90% resistant to a deadly disease. If you’re exposed to it enough, eventually you still catch the disease.’ The quote landed the way Hoskinson intended. The exploit was not a failure of Midnight. It was a demonstration of the problem Midnight exists to solve.
That is the angle every other piece covering this story missed. Outlets ran with the price chart and the ATH low number. The technically important story is in the four lines BlockSec Phalcon published on X at 14:55 UTC: the exploit used a signed-message encoding flaw that allowed a legitimate signature authorizing 3,110 NIGHT to be reused for a withdrawal of 203,001,692 NIGHT, a 65,000x inflation via field-boundary ambiguity in a raw-concatenated hash. That is not a Midnight bug. That is the oldest category of cryptographic implementation error in existence, and it happened because the bridge was trusting a message format it had no way to verify.
The Technical Failure: How a 65,000x Signature Inflation Happened
BlockSec Phalcon’s on-chain forensic analysis identified the root cause precisely. Wanchain’s TreasuryCheck validator, a Plutus V2 smart contract, constructed signed messages by directly concatenating 14 variable-length fields without separators or length markers between them. That encoding method creates field-boundary ambiguity: when you join variable-length strings without delimiters, two different combinations of inputs can produce the same raw hash output. In this exploit, a legitimate authorized signature for a withdrawal of 3,110 NIGHT on BNB Chain was reused on the Cardano side to authorize a withdrawal of 203,001,692 NIGHT, 65,000 times the intended amount, because the raw concatenated hash happened to match.
The attacker ran four transactions in nine minutes, draining 515.2 million NIGHT total, representing approximately 97% of the bridge’s Cardano-side reserves. The Wanchain Cardano lock address held approximately 527 million NIGHT before the attack. It held approximately 12 million after. The attacker funnelled stolen tokens into fresh wallets and liquidated approximately 290 million NIGHT through Cardano DEXs, including one transaction of approximately 203 million NIGHT swapped for roughly 2.8 million ADA. The remaining stolen tokens moved to secondary addresses or were used as lending collateral. No confirmed recovery total had been announced as of July 22.
What did not happen is as important as what did. The Midnight blockchain processed zero unauthorized transactions. Its validators reached consensus normally throughout the exploit window. The Midnight Foundation’s statement was specific: ‘This appears to relate to cross-chain bridge operations and not the Midnight Network itself.’ The wrapped NIGHT on BNB Chain is now largely unbacked, because the custody tokens behind it were stolen. But the native NIGHT on the Midnight Network itself is unchanged. Total supply did not change. The Midnight protocol did not fail. A third-party bridge failed to verify messages it was trusted to verify.
How the Signature Inflation Attack Worked
Four transactions, eight minutes, $13M drained | Sources: BlockSec Phalcon, CryptoTimes, CryptoRank | @cryptonewsbytes
Wanchain TreasuryCheck validator flaw identified
14 variable-length fields concatenated without separators or length markers
Legitimate BNB Chain signature reused on Cardano
Authorized 3,110 NIGHT on BNB. Same hash matched 203M NIGHT on Cardano. 65,000x inflation.
Four transactions, 14:46-14:55 UTC July 20
515.2M NIGHT drained. Bridge reserves: 527M to 12M in 8 minutes.
290M NIGHT sold on Cardano DEXs
One transaction: 203M NIGHT swapped for ~2.8M ADA. NIGHT hit ATL $0.01524.
Wanchain suspends bridge. Midnight Foundation confirms protocol unaffected.
Remaining 225M NIGHT moved to secondary wallets or used as lending collateral.
What never broke: the Midnight blockchain
Validators, consensus, and core protocol operated normally throughout. This is a bridge-layer incident. Token supply unchanged.
Sources: BlockSec Phalcon X post July 21 2026, CryptoTimes forensic analysis, CryptoRank, Midnight Foundation statement | @cryptonewsbytes
Hoskinson’s Argument: Why Bridges Are the Problem ZK Proofs Solve
Hoskinson has been making this argument since before Midnight launched. The dominant cross-chain bridge architecture, including the one Wanchain uses, works by locking assets on one chain and minting wrapped equivalents on another. The custody of the locked assets is protected by a smart contract, a multisig committee, or a validator set. The bridge’s security is therefore the weakest element of: the smart contract code, the multisig key management, and the validator nodes’ operational security. Any one of those three failing is sufficient to drain the custody. Wanchain’s July 20 exploit was the first category: a smart contract encoding flaw in the message verification logic.
The zero-knowledge alternative Hoskinson describes does not require custody at all. In a ZK-native cross-chain system, a transaction on chain A generates a cryptographic proof of its validity. That proof is verified on chain B without chain B needing to trust any custodian, multisig, or validator committee. The proof either passes the mathematical verification or it does not. There is no message format for an attacker to exploit through field-boundary ambiguity, because there is no message being concatenated and signed by a trusted party. Hoskinson told CoinDesk that AI-powered exploit discovery is accelerating the speed at which vulnerabilities in all software are found: “All software is under this enormous assault.” The implication is that any trust-dependent system, regardless of how carefully it was audited, will eventually face an AI-assisted adversary with the time and compute to find every remaining flaw.
The Midnight network itself uses this ZK architecture internally. Its selective disclosure model, where users can prove facts about transactions without revealing underlying data, relies on zk-SNARKs rather than trusted validators for verification. The Wanchain bridge that was exploited was built by a third party using conventional message-signing architecture to bridge NIGHT tokens to BNB Chain. It was never part of Midnight’s own cross-chain infrastructure. Hoskinson acknowledged the distinction while making the broader point: the industry’s continued reliance on legacy bridge architecture is a structural vulnerability that audits cannot fully remediate and only a cryptographic replacement can permanently address.
The Price Recovery and What It Actually Tells You
NIGHT rebounded approximately 19% within 24 hours of the exploit, recovering from the all-time low of $0.01524 to approximately $0.022. Hoskinson noted pointedly that outlets reporting the crash failed to mention the rebound. The recovery is not evidence that the incident was minor. It is evidence that the market, after the initial panic sell, correctly identified that the Midnight protocol itself was not compromised and that the stolen tokens, representing approximately 2.15% of the 24 billion total supply, did not represent a fundamental change in Midnight’s network security or utility.
The structural damage is specifically to the Wanchain bridge’s BNB Chain-side wrapped NIGHT positions. Those tokens are now largely unbacked because the Cardano-side custody that backed them was drained. Holders of wrapped NIGHT on BNB Chain face real exposure. The native NIGHT on Midnight does not face the same issue. The distinction between protocol-level security and bridge-layer security is the single most important concept for any NIGHT holder to understand coming out of this incident, and it is the concept Hoskinson has been trying to articulate since the first security notice dropped on July 20.
NIGHT Price: July 20-22, 2026
ATH low to 19% rebound | Sources: CoinGecko, CryptoRank, AMBCrypto | @cryptonewsbytes
Sources: CoinGecko, AMBCrypto, CryptoRank Jul 21-22 2026 | @cryptonewsbytes. Not financial advice.
The Broader Context: Bridge Hacks in 2026 and the AI Threat
The Wanchain-Midnight incident is the latest in a 2026 pattern CNB has been tracking across the year. Earlier in July, Ostium lost $18M through an oracle signer key compromise on Arbitrum. In June, Taiko lost $1.7M through a leaked SGX enclave key on GitHub. Polymarket lost $3.1M through a supply chain attack. SecondFi, whose wind-down CoinDesk reported on July 22 following a $2.4 million ADA wallet theft, is the fourth Cardano-adjacent incident in a single month. The pattern in every case: the protocol-level smart contract or consensus mechanism was not the entry point. The infrastructure surrounding it was.
Hoskinson’s AI-powered exploit discovery argument is the most forward-looking part of his response. The conventional security model assumes that a sufficiently audited codebase is safe until a human researcher finds a new class of vulnerability. AI changes that assumption. A large language model with access to a codebase and a vulnerability database can generate and test exploit hypotheses at a speed no human team can match, and the compute cost to do so is falling every quarter. If Hoskinson is correct that AI is already accelerating the rate at which new vulnerabilities are being discovered and exploited in Linux kernel code, the same dynamic will arrive in crypto bridge infrastructure on a similar timeline. Legacy trust-dependent bridge architecture will face increasing pressure not because the code gets worse but because the adversary tooling gets better.
Midnight’s ZK architecture is the structural answer to that trend. It removes the category of trust-dependent message verification that allowed the Wanchain exploit to succeed. Whether Midnight’s own bridge infrastructure eventually ships with ZK-native cross-chain proofs rather than message-signing validators is the question that Hoskinson’s July 22 comments implicitly raise. If it does, the NIGHT token’s loss on Monday becomes, in retrospect, the most expensive proof-of-concept for the product thesis Midnight has been articulating since its February 2026 launch at Consensus Hong Kong.
2026 Bridge and Infrastructure Exploits: The Pattern
Protocol was never the entry point. Infrastructure surrounding it was. | @cryptonewsbytes
| Incident | Date | Amount | Entry point | Protocol affected? |
|---|---|---|---|---|
| Wanchain (Midnight NIGHT) | Jul 21, 2026 | ~$13M | Bridge message encoding flaw (65,000x signature inflation) | No. Midnight protocol unaffected. |
| Ostium (Arbitrum) | Jul 15, 2026 | $18M | Oracle signer key compromised, future-dated prices | No. Contracts worked correctly. |
| Taiko (Ethereum L2) | Jun 22, 2026 | $1.7M | SGX signing key leaked on GitHub | No. Bridge contracts worked correctly. |
| Polymarket | Jun 25, 2026 | $3.1M | Vendor supply chain, frontend JS injection | No. Chain untouched. |
| SecondFi (Cardano/Yoroi) | Jun 2026 | $2.4M ADA | Wallet key generation flaw (Yoroi) | No. Cardano protocol unaffected. |
In every 2026 incident, the underlying protocol operated correctly. The failure was in the surrounding infrastructure layer. | @cryptonewsbytes
Frequently Asked Questions
Was the Midnight blockchain hacked?
No. The Midnight Foundation confirmed that the Midnight blockchain, its validators, consensus mechanism, and core protocol were completely unaffected by the Wanchain bridge exploit. The vulnerability was in Wanchain’s TreasuryCheck validator, a third-party Plutus V2 smart contract that Wanchain built and operates independently. The Midnight protocol processed no unauthorized transactions.
What happens to wrapped NIGHT tokens on BNB Chain?
The wrapped NIGHT on BNB Chain is now largely unbacked because the Cardano-side custody that backed it was drained. Holders of Wanchain-wrapped NIGHT on BNB face real exposure. Wanchain has suspended the bridge while it investigates. Native NIGHT on the Midnight Network is unaffected and the total supply did not change. The distinction between protocol-level NIGHT and bridge-wrapped NIGHT is critical for any current holder.
What is a signed-message encoding flaw and how did it enable a 65,000x inflation?
Wanchain’s TreasuryCheck validator built authorization messages by joining 14 variable-length data fields in sequence without separators or length markers between them. This created field-boundary ambiguity: different combinations of inputs can produce the same raw hash. An attacker found a combination where a legitimate authorized signature for 3,110 NIGHT on BNB Chain produced the same hash as a Cardano withdrawal of 203,001,692 NIGHT, 65,000 times the intended amount. The validator accepted the reused signature as valid because mathematically it was, just not for the amount it authorized.
What is Hoskinson’s proposed solution and does Midnight already use it?
Hoskinson argues ZK-native cross-chain systems replace trust-dependent bridge infrastructure with cryptographic proofs. Instead of a validator committee signing messages that could be forged or replayed, the sending chain generates a zero-knowledge proof of a transaction’s validity that the receiving chain verifies mathematically. No trusted party, no message format to exploit. The Midnight network’s internal architecture uses ZK proofs for its selective disclosure model. The Wanchain bridge that was exploited was third-party infrastructure using conventional message-signing, not ZK-native design.
Further Reading
The same pattern from July 15: infrastructure surrounding the protocol failed, not the protocol itself. Oracle signer key compromise on Arbitrum.
June’s version of the same failure mode. SGX signing key leaked. Bridge drained. Taiko L2 protocol untouched.
The full Midnight architecture, NIGHT and DUST dual-token model, and the Hawaiian roadmap. What Midnight is building and why Hoskinson thinks ZK is the permanent answer to bridge security.
This article is for informational purposes only and does not constitute financial advice. Sources: CoinDesk Jul 22 2026 (Oliver Knight), TokenPost Jul 22 2026, CryptoTimes Jul 21 and 22 2026, BlockSec Phalcon X post Jul 21 2026, AMBCrypto Jul 21 2026, BeInCrypto Jul 21 2026, CryptoRank Jul 21 2026, Wanchain official statement Jul 20 2026, Midnight Foundation statement Jul 20 2026, CoinGabbar Jul 22 2026, HokaNEWS Jul 22 2026, crypto.news Jul 21 2026. Published July 22, 2026.

