ME News reports that on July 21 (UTC+8), according to BlockSec Phalcon monitoring, the Cardano cross-chain bridge of Wanchain was attacked, resulting in the theft of approximately 515 million NIGHT tokens. Preliminary investigations indicate that the root cause appears to be a non-injective encoding issue in the TreasuryCheck validator for signed messages. This signed message was generated by raw concatenation of 14 variable-length redeemer fields using the `AppendByteString` fold operation, without delimiters or length prefixes. Different field-value tuples may produce identical byte strings, leading to identical hashes and enabling the reuse of valid signatures. (Source: Foresight News)
Wanchain's Cardano cross-chain bridge hacked; 515 million NIGHT stolen
KuCoinFlashShare
A cross-chain bridge connecting Wanchain and Cardano was exploited on July 21 (UTC+8), resulting in the theft of approximately 515 million NIGHT tokens. Initial findings indicate a vulnerability in the TreasuryCheck validator’s non-injective encoding method. Attackers exploited the concatenation of 14 redeemer fields using `AppendByteString` without separators or length prefixes, enabling signature reuse. This cross-chain bridge vulnerability allowed unauthorized withdrawals.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.
