Disclaimer: The opinions expressed by our writers are their own and do not represent the views of U.Today. The financial and market information provided on U.Today is intended for informational purposes only. U.Today is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.
The Midnight Foundation has released an official update on the response to the attack on Wanchain's Cardano-BNB cross-chain bridge. The developers quickly brought partner exchanges into the investigation: Binance, OKX, Kraken, KuCoin, Bybit, Gate, and MEXC introduced emergency measures to completely block the movement of the stolen funds.
The coordinated response from the platforms prevented the liquidation of 515 million NIGHT tokens, worth approximately $9 million, stolen from the treasury of a third-party smart contract.
Following the incident, NIGHT temporarily plunged by more than 30% on decentralized exchanges, reaching an all-time low of $0.016.
How exchanges trapped a hacker after a $9 million Cardano bridge code exploit
The main purpose of the Midnight Foundation's statement was to confirm that the stolen millions had been isolated within centralized systems. At the foundation's request, the exchanges immediately blacklisted the attacker's wallets, temporarily froze associated accounts, and suspended NIGHT deposits and withdrawals.
This prevented the hacker from laundering most of the stolen funds. However, the attacker managed to sell approximately 290 million tokens on Cardano decentralized exchanges, where automated freezes are impossible, causing the short-term price collapse.

The Midnight Foundation separately emphasized that both the Midnight privacy-focused Layer 1 network and the Cardano blockchain continue to operate normally. The incident was not caused by a systemic failure within either project, and the vulnerability was isolated exclusively within the Wanchain bridge code, which had been operating for approximately two years.
According to analysts at BlockSec's Phalcon platform, the hacker exploited a flaw in the TreasuryCheck validator. The contract verified 14 data fields placed consecutively without delimiter characters.
The attacker took a legitimate BNB Chain signature intended for a transfer of just 3,110 NIGHT and, due to the absence of clear boundaries between the data fields, reused it on the Cardano side, inflating the transaction by 65,000 times to 203 million NIGHT in a single operation.
The Wanchain team has now completely disabled the bridge while it patches the vulnerability in its architecture. However, the main challenge remains the resulting imbalance: after the Cardano treasury was drained, wrapped NIGHT tokens on BNB Chain were temporarily left without collateral backing.
The Midnight Foundation is continuing its investigation and has urged the community to rely only on official communication channels to avoid phishing attempts during the incident response.


Dan Burgin
U.Today Editorial Team