In the quiet of a July afternoon, the Wanchain bridge on Cardano began to bleed. At 14:46 UTC, an attacker drained approximately 5.15 billion NIGHT tokens from the bridge’s locking address — a reserve that represented 97% of all NIGHT held to secure the wrapped version of the token on BNB Chain. Within minutes, the attacker started selling 290 million NIGHT on Cardano decentralized exchanges, sending the token to an all-time low of $0.01524 and crashing its market value by 27% in a single day. The bridge was paused within an hour, but the damage was already done.
This is not just another hack. It is a forensic footprint of how centrally managed bridges — those that rely on a single locking address and a trusted custodian — become the single point of failure for an entire token ecosystem. Midnight Foundation quickly issued a statement that its own network remained unaffected. But the truth is more complex: when the bridge that provides the only liquid path between Cardano and BNB Chain is compromised, the token’s liquidity, reputation, and utility suffer a blow from which it may never recover.
Tracing the code back to the silence of the attack, we find that only the NIGHT token was taken. Other bridged assets remained untouched. This is a crucial detail. It suggests that the vulnerability was not in the bridge’s core consensus mechanism but in the token-specific interaction logic — likely a flaw in how the bridge validated cross-chain messages for NIGHT transfers, or a privilege escalation in the whitelist that allowed the attacker to call a withdrawal function without the corresponding lock on Cardano. The fact that the attacker could drain the entire NIGHT reserve in under ten minutes points to either a private key compromise or an exploitable administrative function with no multi-signature delay.
We audit not to judge, but to understand. In my years analyzing contract-level security — from the Bancor V1 overflow bugs in 2017 to the OpenSea signature forgery in 2021 — I have seen this pattern repeat. A bridge that holds all its eggs in a single basket invites catastrophe. Wanchain’s locking address contained 5.27 billion NIGHT as of the attack. After the exploit, the reserve fell to approximately 12 million NIGHT — a 97% drop. The token’s peg to its wrapped version on BNB Chain is now effectively broken unless Wanchain or Midnight Foundation commits to a full restitution plan.
The market reaction was swift and brutal. NIGHT price collapsed from around $0.021 to a new all-time low of $0.01524. The attacker sold 290 million tokens on Cardano-based DEXs, applying direct sell pressure. But 2.25 billion NIGHT remain in the attacker’s wallet — a looming overhang that can crash the token further with any additional sale. Liquidity on BNB Chain for Wrapped NIGHT has likely evaporated as market makers withdrew after the reserve was emptied.
Authenticity is not minted, it is verified. Midnight Foundation’s statement — “the Midnight network and its core protocols were not affected” — is technically correct but misleading. While the bridge attack did not compromise Midnight’s own chain, it destroyed the primary channel through which NIGHT circulates across chains. For users holding Wrapped NIGHT on BNB Chain, the token now exists in a state of limbo: its backing is gone, and its redemption value depends entirely on the goodwill of the bridge operators. This is not a mere technical glitch; it is a failure of trust architecture.
Here is the contrarian angle the mainstream coverage misses: the industry has been so focused on the narrative of “multichain expansion” that we have normalized custodial bridges as a temporary necessity. But this attack proves that custodial bridge security is not a scaling problem — it is a structural vulnerability. LayerZero, Wormhole, and other more decentralized designs rely on independent validators or multi-party computation to guard assets. Wanchain’s model, by contrast, concentrated all trust in a single address controlled by the foundation. When that single point fails, the entire liquidity layer collapses. The fact that only NIGHT was stolen does not make the bridge safer for other tokens; it merely means the attacker chose to target that specific contract path. The same vulnerability could be exploited for any other asset if it shares the same code base.
Layer two is a promise, not just a layer. In the quiet, the protocol reveals its true intent. The Wanchain bridge breach exposes a fundamental truth: we have been treating bridges as plumbing rather than as critical infrastructure that demands the same rigorous security as layer-1 consensus. Until bridges adopt transparent, audited, and decentralized security models — with sovereign validation of cross-chain messages — every token that depends on a custodian bridge is living on borrowed time. Midnight Foundation now faces a choice: either negotiate a restitution plan that restores trust, or watch its token become a case study in how not to design cross-chain liquidity.
The vulnerability is not in the code alone; it is in the assumption that a single entity can be trusted indefinitely. As the dust settles, the question remains: was this a hack, or a lesson we refuse to learn?


