A crypto bridge is supposed to feel like a shortcut. This week, it looked more like an open vault.
Hackers exploited a Wanchain bridge route linking Cardano and BNB Chain, draining about 515 million NIGHT tokens. The tokens were valued at roughly $9 million when the breach came to light.
The affected route was suspended after the attack. That move stopped further damage on that path, but not before the stolen tokens shook confidence and hit the market price.
NIGHT fell by more than 30% during the sell-off. It touched a record low near $0.015 before recovering part of the loss.
For Indian crypto users watching from Mumbai, Bengaluru, Delhi or Dubai, the lesson is blunt. A blockchain can remain secure while a service built around it still breaks.
That distinction matters here.
The attack targeted Wanchain-operated bridge infrastructure. It did not compromise Cardano’s core network. Midnight Foundation also said its validators, consensus system and wider network remained secure.
In simple terms, the road between two places was attacked. The cities themselves did not fall.
That may sound comforting, but it does not fully protect investors. If a token trades on markets, fear can crush its price even when the base chain keeps running.
The stolen NIGHT came from a treasury address used to support transfers across the bridge. Bridges work by locking assets on one network and issuing matching assets on another.
That design creates convenience. It also creates large pools of tokens in one place.
Hackers love those pools because one successful exploit can move huge value within minutes.
Investigators traced the breach to a flaw in how the bridge encoded transaction data before approval. The affected validator contract reportedly packed 14 variable-length fields into one message.
The problem was that the message lacked strong separators or fixed boundaries.
That sounds technical, but the risk is easy to understand. If a system cannot clearly tell where one field ends and another begins, attackers can rearrange meaning.
Different sets of transaction data can then create the same encoded message. That allows a valid signature for one action to be reused for another.
In this case, attackers allegedly took a legitimate signature linked to about 3,110 NIGHT. They then manipulated it to approve withdrawals of more than 200 million tokens in one operation.
More transactions followed. The total removed reached about 515 million NIGHT.
This is the part retail buyers often misunderstand. Crypto security is not only about a famous blockchain’s reputation.
It also depends on smart contracts, validators, signing rules, message formats and off-chain services. One weak component can undo the promise of the rest.
That is why bridges remain one of crypto’s most sensitive pieces of infrastructure. They connect isolated networks, but they also introduce fresh trust points.
Wanchain has operated since 2017 and markets itself as a decentralised interoperability network. It connects dozens of blockchain platforms, including Ethereum-compatible and non-Ethereum networks.
That history did not stop this breach.
The incident shows how new assets and chain integrations can create new attack surfaces. A bridge can work for years and still face fresh risk when designs change or complexity rises.
After the abnormal activity was detected, Wanchain halted the relevant bridge service. It also began working with security specialists, exchanges and the Midnight team.
Several large exchanges restricted NIGHT deposits and withdrawals or blocked addresses tied to the stolen funds. That step aimed to stop the attacker from cashing out through centralised platforms.
But crypto does not move only through big exchanges.
Some stolen NIGHT moved through Cardano-based decentralised exchanges. Those venues do not have the same central account controls, so freezing activity becomes harder.
That movement added selling pressure and helped push the token lower.
For ordinary buyers, this is where the money risk becomes very real. Even if an attacker cannot instantly convert every token, market fear can hurt holders within minutes.
A 30% fall is not an abstract chart event. It can wipe out weeks or months of gains for people who bought near recent levels.
The reported loss also shifted in dollar terms. Estimates ranged from about $9 million to more than $13 million because NIGHT’s price moved sharply during and after the attack.
That is another crypto complication. The size of a hack can change while investigators are still tracking the stolen assets.
Midnight sits in a particularly sensitive part of the market because it focuses on privacy. The blockchain, developed with support from Input Output, aims to let applications protect confidential information while still allowing selective disclosure and regulatory controls.
NIGHT supports participation in that network. It also supports the generation of DUST, a resource designed to pay for transactions without exposing user identities.
That privacy angle makes confidence especially important. If users doubt the safety of surrounding infrastructure, they may hesitate before moving assets through connected services.
The breach has renewed calls for stronger bridge design. Cardano’s founder has argued that the sector should move toward zero-knowledge-based bridges.
The idea is to verify transactions cryptographically while reducing dependence on operators and multisignature arrangements.
Security specialists have long warned about signature replay risks. A signed message must clearly bind every transaction field to its type, length, destination chain and intended contract.
Without that discipline, approval for one transaction can become a weapon for another.
For the Gulf crypto ecosystem, including Dubai’s fast-growing digital asset market, the story lands at an awkward time. Regulators and licensed platforms want to show that crypto can mature beyond speculative trading.
But bridge hacks keep reminding users that infrastructure risk has not disappeared.
Dubai and the wider UAE have tried to build a regulated environment for virtual assets. That can improve standards at licensed exchanges and service providers.
Yet regulation cannot magically fix every smart contract or third-party bridge used across global networks.
Indian investors should draw a practical line from this incident. Do not treat all crypto exposure as equal.
Holding a token, staking it, bridging it, trading it on a decentralised exchange and using wrapped assets all carry different risks. The brand name on the token does not explain the full chain of custody.
The immediate focus now sits on asset tracing, exchange controls and whether any stolen NIGHT can be frozen or recovered. Investigators are still following wallet movements.
The broader question is more uncomfortable. If a bridge can be drained through message encoding errors, how many similar systems deserve fresh audits before users trust them with serious money?
Crypto often sells speed and access. This breach shows the bill for that speed.
When automated systems fail, they fail fast. And by the time retail investors understand what happened, the price chart may already have delivered the verdict.