Cardano↔BNB bridge was hacked: exchanges join forces to counterattack.

CN
4 hours ago

On July 21, 2026, according to existing materials, the Cardano↔BNB cross-chain bridge operated by Wanchain was confirmed to have suffered a security attack of an exploit nature. After the cross-chain channel was breached, assets on the bridge were transferred abnormally and migrated along the existing path from the chain, ultimately observed entering associated accounts of multiple centralized exchanges. This incident was first disclosed by the Midnight Foundation through public channels, providing a time anchor and basic framework for the outside world; however, the specific technical methods of the attack and the scale of the stolen assets have yet to be disclosed. After suspicious funds arrived at exchanges, at least seven platforms, including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC, quickly coordinated by identifying relevant addresses, freezing involved accounts, blacklisting the attackers' wallets, and suspending or limiting the deposits and withdrawals of the NIGHT token, bringing this cross-chain bridge attack into the game of power boundaries between CeFi and DeFi, making the question of "what role centralized platforms should play when decentralized systems go out of control" once again a reality that the industry must face.

Breached Cardano↔BNB Cross-Chain Bridge

In this incident, the breach stemmed from an apparently inconspicuous yet critically important infrastructure—the Cardano↔BNB cross-chain bridge operated by Wanchain. As a protocol focusing on cross-chain interoperability, Wanchain connects assets across two independent public chains, allowing holders to migrate and configure assets between the Cardano and BNB chains, thus making this bridge a "traffic artery" between the two major ecosystems, bearing daily cross-chain transfers and more complex asset pathway designs.

According to publicly disclosed information, on July 21, 2026, this Cardano↔BNB cross-chain bridge was confirmed to have encountered a security attack, with the nature of the event defined as an exploit rather than normal on-chain governance or parameter adjustment. The attacker initiated abnormal operations utilizing this bridging channel, causing on-chain assets that should be protected by protocol rules to be illegally transferred, with funds being extracted from one side of the bridge and redirected to wallets controlled by the attacker. The specific attacking methods and the amount stolen have not yet been made public, and this uncertainty itself reinforces the market's perception of risk pertaining to cross-chain infrastructures. In the past few years, cross-chain bridges like Ronin and Wormhole have experienced attacks amounting to hundreds of millions of dollars, already branding the term "bridge" with a high-risk label; this breach of the Cardano↔BNB bridge adds a stark warning to the timeline of the prolonged game between hackers and cross-chain protocols.

Midnight Disclosure and Exchanges' Pursuit of On-Chain Assets

On July 21, 2026, public information indicated that the Midnight Foundation was the first to break the silence, confirming through official channels that the Cardano↔BNB cross-chain bridge operated by Wanchain had encountered an exploit. In the notice, Midnight explicitly pointed out the nature of the event and the affected channel, providing a basic framework for subsequent assessments by all parties, and quickly elevating this attack from an isolated on-chain anomaly to a publicly scrutinized event. As the notice spread, the on-chain trajectory of the involved funds was further labeled, and related assets had been tracked to associated accounts in multiple centralized exchanges, with the attackers' attempts to cash out at exchange exits beginning to take shape.

After the funds were identified entering exchanges, the security cooperation mechanism was quickly activated. Current information indicates that platforms like KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC sequentially engaged in joint handling: on one hand, freezing the locked accounts involved to cut off the attacker’s further operational space; on the other hand, incorporating the attackers' associated wallet addresses into their respective blacklist databases, preventing the same addresses from shuttling frequently between different platforms. Additionally, multiple exchanges took more direct risk control actions concerning the NIGHT token closely related to this incident, pausing or limiting its deposits and withdrawals to narrow potential capital exits. Even so, publicly available information has yet to disclose the specific scale of the stolen assets, nor provided details on the internal flow of funds within each platform, indicating that the market can currently only confirm that some of the attacked funds have entered the exchange system, while the deeper whereabouts and the recoverable proportion remain an investigation clue that has not been fully illuminated.

Formation of Security Alliance: CeFi Intervenes in DeFi Risk Control Scene

When suspicious assets flow into the exchange system through the Cardano↔BNB cross-chain bridge, the main characters of the story quickly switch from on-chain contracts to risk control teams of leading platforms. Existing materials show that at least seven exchanges, including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC, responded within a short time: on one side, blacklisting the wallets based on public information about the associated addresses and fund paths to restrict further deposits and withdrawals; on the other side, freezing the involved accounts and suspending or tightening deposits and withdrawals of NIGHT tokens according to their respective standards. The synchronization of blacklists, once risk addresses are identified, spreads across multiple platforms, becoming the "default tactic" for the industry in handling on-chain attacks, and the collaborative capability of such temporary security alliances was again validated in this incident.

However, when decentralized protocols encounter issues, the model of centralized platforms intervening to "pull the plug" inherently carries tension. On one hand, exchanges possess control over the risk assessment and freezing of incoming assets, making them a key link in blocking the attackers' cash-out paths at the moment the Wanchain Cardano↔BNB cross-chain bridge was breached; on the other hand, the blacklisting and collective freezing rely on centralized discretion from the platforms, raising unavoidable controversies over how to delineate the boundary between attacked funds and innocent addresses, when to lift temporary measures, and whether it will affect ordinary users' rights to asset usage. As similar incidents continue to accumulate, "allowing CeFi to act as the last line of defense for DeFi in extreme scenarios" is becoming a factual industry practice, while how this defense line should set boundaries remains an open question that needs continuous verification in subsequent investigations and more public information.

Concentration of Fund Pools Makes Cross-Chain Bridges Hacker Favorites

Getting centralized exchanges to step onto the front line post-incident often requires that the cross-chain bridge itself has already become a weak link on the battlefield. The structure of cross-chain bridges inherently makes them prime targets for hackers: they host and lock substantial amounts of assets across multiple public chains, forming a concentrated fund pool. As long as the custody or verification stages of the bridge are breached, a few addresses controlled by attackers can withdraw assets on a large scale from the bridge contract and transfer them to exchange accounts along existing cross-chain paths, with single point failures quickly evolving into systemic risks for multi-chain assets.

This structural vulnerability is not new. Previously, the Ronin and Wormhole cross-chain bridges suffered attacks amounting to hundreds of millions of dollars, with cases of verification nodes being bypassed and cross-chain messages being falsified creating a clear risk profile for the industry: the validation of cross-chain messages relies on multiple nodes and complex contract logic, and each additional layer component adds another potential attack surface. Once there is a gap in the verification system, the assets under centralized custody can be “legally” transferred out of the bridge in a very short time. The Cardano↔BNB cross-chain bridge operated by Wanchain was confirmed as an exploit incident on July 21, 2026, with involved assets being transferred by the attackers' addresses from the bridge side and entering accounts in multiple exchanges, highly aligning with the industry's long-standing concerns regarding the security shortcomings of cross-chain bridges, further proving that cross-chain infrastructure remains in a prolonged risk exposure period that requires continuous reinforcement.

Signals to Watch Closely After This Attack

In the period following this incident, several variables will determine the final outcome of the cross-chain attack. First is the progress of asset recovery and bridge service restoration: currently, publicly available information has not disclosed the specific amount stolen and the technical methods, nor has it clearly shown whether Wanchain has suspended or repaired the Cardano↔BNB cross-chain bridge. If the Midnight Foundation further announces the results of investigations and asset tracking, particularly regarding the freezing status of involved addresses on the exchange side, the recovery ratio, and whether the bridge will be restarted, these will be core signals for assessing the damage boundaries of the event and the potential for trust restoration. Secondly, it is important to observe whether the collaborative security response among multiple exchanges will solidify into a standard emergency process for cross-chain security events—this includes sharing blacklists and unified adjustments to deposit and withdrawal strategies for involved tokens (like NIGHT), which directly affects users' operational space and the circulating environment for projects, as well as reshaping market expectations on "whether attacks can be quickly contained post-occurrence." Finally, whether ordinary users or project parties operating across multiple chains need to reassess their risk exposure and trust assumptions regarding cross-chain bridges: whether single point bridging has become a weak link in their architecture, which assets should not be exposed to bridges long-term, and whether they are still willing to assume the same counterparty risks in the absence of fully transparent technical details—these answers will determine who continues to pay for cross-chain efficiency and who will actively allocate costs for safety redundancy.

Join our community to discuss and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink