BlockSec says Wanchain’s Cardano bridge was exploited, with about 515 million NIGHT stolen
BlockSec Phalcon said Wanchain’s Cardano cross-chain bridge was hit by an exploit, resulting in the theft of about 515 million NIGHT tokens. In its initial findings, the security team pointed to an apparent non-injective encoding issue in the TreasuryCheck validator’s handling of signed messages. The message in question was built by raw concatenation of 14 variable-length redeemer fields using an `AppendByteString` fold, without separators or length prefixes. That construction can allow different field-value tuples to produce the same byte string. If the byte string is identical, the resulting hash can also match, which in turn may let a valid signature be reused. The account is based on BlockSec’s monitoring and an early-stage investigation described in the source material.








