source avatarDusty Field

Share

Three items in the last 48 hours: a cross-chain bridge exploited through message-encoding reuse, a DeFi front-end announcing permanent shutdown after a vault exploit forced it out of operation, and two Uniswap governance votes live now that would extend the protocol's fee-burn mechanism to new chains and versions. Wanchain / Midnight: On July 20-21, 2026, BlockSec's Phalcon monitor identified an exploit against Wanchain's Cardano-to-BNB Chain bridge, draining approximately 515.2 million NIGHT tokens from the bridge treasury, worth roughly $10 million at prevailing prices. The attack completed in four transactions over an eight-minute window. BlockSec identified the root cause as a non-injective signed-message encoding flaw in the bridge's TreasuryCheck validator: the Plutus V2 contract hashes 14 variable-length redemption fields through raw concatenation without delimiters, which allows different field combinations to produce the same byte string and reuse the same signature. The attacker replayed a legitimate BSC transaction authorizing roughly 3,110 NIGHT to extract approximately 203 million NIGHT in a single redemption on the Cardano side, a roughly 65,000x inflation via field-boundary ambiguity. The stolen tokens were funneled into Cardano wallets before roughly 90% was liquidated through Cardano DEX swaps. Wanchain took the bridge offline. The Midnight Foundation confirmed the Midnight blockchain and its core protocol were not compromised. NIGHT is Midnight's governance token and the source of DUST, the network resource for transactions and smart contract execution. Midnight launched its mainnet in March 2026, and NIGHT remains publicly transferable, making the token held in bridge custody a live attack surface independent of Midnight's own security posture. SummerFi: On July 20, 2026, https://t.co/SVnV4cvqcc and its development company https://t.co/SVnV4cvqcc Labs formally announced wind-down of the platform after seven years, citing a July 6 exploit on the Lazy Summer Protocol as the direct cause. The exploit manipulated two USDC vaults on Ethereum mainnet in a single atomic transaction, extracting roughly $6.04 million by inflating reported assets and initiating an oversized withdrawal against a $65.4 million flash loan. The attack hit user deposits, protocol-owned capital, and the team's own reserves simultaneously, eliminating the operational runway needed to rebuild. The https://t.co/SVnV4cvqcc interface and customer support channels remain live until August 31, 2026. After that date, responsibility for withdrawals, remediation, and continued protocol operation transfers entirely to the Lazy Summer DAO. No shutdown date for the underlying protocol has been set because it operates under separate decentralized governance. The Lazy Summer vaults route deposits across lending strategies including Aave and Morpho; the specific attack vector was a valuation flaw in one of those strategy adapters that held outdated NAV figures. CertiK attributed the exploit to a flash loan attack, while SummerFi characterized it as NAV manipulation, and no independent reconciliation of the two accounts has been published. The pre-exploit TVL was between $22 million and $25 million. Uniswap: Two on-chain governance proposals opened July 19, 2026, with voting open through July 26. Proposal 100 would activate protocol fees on select Uniswap v4 pools across seven chains: Ethereum, Arbitrum, Base, BNB Chain, Polygon, Optimism, and Robinhood Chain. The targeted pool categories are static-fee pools without hooks, continuous clearing auction pools, and aggregator hook pools. Proposal 99 would extend v2 and v3 protocol fees to Robinhood Chain, where all three Uniswap versions deployed on July 1, 2026. Both proposals route collected fees into the TokenJar and Firepit burn system established under December 2025's UNIfication vote, where fees accumulate and can only be withdrawn when equivalent UNI is burned. That link between fee flow and supply reduction is immutable once deployed and cannot be altered by subsequent governance. As of July 19, each proposal held roughly 2.94 million UNI in favor against a 40 million UNI quorum threshold, approximately 7.4% of the requirement. A temperature check run July 7-12 drew 93% support with 13.9 million UNI voting in favor. The quorum gap means turnout, not sentiment, is the open variable through July 26. Robinhood Chain is an Arbitrum Orbit chain, so governance execution on that chain runs through retryable tickets via its Inbox and the L2 alias of the Uniswap Timelock, a routing dependency that must succeed for the fee switch to land on-chain for that deployment.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.