Wanchain Hack
Incident Overview
On July 21, 2026, the cross-chain interoperability protocol Wanchain suffered a security exploit targeting its Cardano-BNB Chain bridge, resulting in the unauthorized minting and withdrawal of over 203 million NIGHT tokens and a realized loss of approximately $500,000 (2.83 million ADA).
The exploit targeted the cross-chain message verification pathway between BNB Chain and Cardano. The attacker crafted forged cross-chain payload messages and submitted fake execution proofs to the bridge contract on Cardano without depositing backing assets on the source chain. This logic failure caused the contract to validate the forged messages and fraudulently mint/release 203,001,692 NIGHT tokens directly to the attacker's wallet.
The exploiter immediately dumped the falsely minted tokens on Cardano decentralized exchanges, swapping them for 2,831,361 ADA before Wanchain officially paused bridge activity to halt further withdrawals.
Cardano Attacker Address: addr1qysj48kpy8qra2g64scvu79n489qrv2uys5ggsrun29v5f5udqxfpr7x0pqfl6khjwv6vm0k8s3spn6h0zfrwszfqgcqeld8kj
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Wanchain, these are the critical security checks that could have prevented this incident (July 2026).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Wanchain
The Wanchain hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.