BlockSec Phalcon said Wanchain’s Cardano cross-chain bridge was hit by an exploit, resulting in the theft of about 515 million NIGHT tokens. In its initial findings, the security team pointed to an apparent non-injective encoding issue in the TreasuryCheck validator’s handling of signed messages. The message in question was built by raw concatenation of 14 variable-length redeemer fields using an `AppendByteString` fold, without separators or length prefixes. That construction can allow different field-value tuples to produce the same byte string. If the byte string is identical, the resulting hash can also match, which in turn may let a valid signature be reused. The account is based on BlockSec’s monitoring and an early-stage investigation described in the source material.
BlockSec Phalcon said Wanchain’s Cardano cross-chain bridge was exploited, with about 515 million NIGHT stolen.
Its initial investigation said the issue appears to stem from a non-injective encoding problem in the TreasuryCheck validator’s processing of a signed message. That message was formed through raw concatenation of 14 variable-length redeemer fields using an AppendByteString fold, with no separator or length prefix added.
Under that design, different field-value tuples may generate the same byte string. That can lead to the same hash and allow a valid signature to be reused.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.