@kitto
Wanchain's Cardano-BNB Chain cross-chain bridge has been attacked, resulting in the theft of 515 million NIGHT tokens, valued at approximately $10 million. According to an analysis by security firm BlockSec, the hack was caused by an encoding flaw in the bridge's validator system. Attackers exploited a vulnerability where data fields were concatenated without delimiters, allowing them to reuse signatures and withdraw up to 65,000 times the intended amount.
Following the attack, a significant portion of the stolen tokens were rapidly sold on Cardano-based decentralized exchanges, causing the price of the NIGHT token to temporarily crash by over 30%, hitting an all-time low. Fortunately, the Midnight Foundation promptly clarified that this vulnerability is unrelated to the security of the Midnight network itself and is confined solely to Wanchain's external bridge infrastructure. They confirmed that core systems, including the main network and consensus algorithms, are operating securely.
This incident serves as a stark reminder that even with excellent native mainnet security, a single failure in the validation process of a bridge connected to external assets can severely impact the entire ecosystem. The encoding mistake of serializing variable-length fields without delimiters is a classic security blind spot that has occurred frequently in the past. For the time being, bridge users should carefully monitor for the normalization of the affected route and watch for potential additional sell pressure from the stolen tokens.
Related Links