NIGHT rebounded after a sharp sell-off, while Charles Hoskinson used the exploit to argue that cross-chain security should move away from legacy bridges toward cryptographic proof-based designs.
Wanchain’s Cardano-to-BNB Chain bridge was exploited after about 515 million NIGHT tokens were drained from the Cardano-side lock address backing bridged NIGHT, briefly sending the token to an all-time low near $0.015 and valuing the stolen assets at roughly $9 million to $10 million around the sell-off. NIGHT later recovered after an earlier plunge of roughly 43% as stolen tokens were dumped through the legacy bridge. Wanchain suspended the affected bridge and began investigating, while Midnight Foundation said the breach was confined to third-party bridge infrastructure and did not affect Midnight’s protocol, validator network, consensus system, core infrastructure or the NIGHT smart contract on Cardano. BlockSec said its preliminary analysis pointed to a possible flaw in the TreasuryCheck validator’s signed-message encoding that may have allowed a previously valid signature to be reused with different transaction data. Charles Hoskinson said the incident highlighted broader pressure on software security and argued that systems such as Midnight should replace bridge operators and multisigs with cryptographic proofs, as major exchanges including Binance, Kraken, KuCoin, Bybit, OKX, Gate and MEXC coordinated to restrict movement of the stolen funds.