News linked to both this project and an event.
Odaily News: Cross-chain infrastructure provider Wanchain has announced that it is proposing a white hat settlement to the attacker responsible for the July 20 exploit of the Wanchain Cardano cross-chain bridge, during which NIGHT tokens were stolen. The proposal requires the attacker to return 90% of the stolen NIGHT tokens before 20:00 Beijing time on August 6, and allows them to keep 10% as a white hat bounty. If the tokens are returned on time, Wanchain will regard the action as white hat behavior and will not pursue civil litigation.
据 Wanchain 官方 X 账号发文,2026 年 7 月 20 日,Wanchain Bridge Cardano 跨链桥遭到攻击,黑客盗取 NIGHT 代币。Wanchain 随即向攻击者发出公告,要求其在 8 月 6 日 UTC 12:00 前归还 90% 被盗 NIGHT 代币,可保留 10% 作为白帽赏金,并承诺不追究民事责任。 目前,有社区用户指出黑客已将 NIGHT 代币在 DEX 上完成兑换,NIGHT 代币价格下跌逾 30%,现报 0.0188 美元。
According to CoinDesk, the Cardano wallet SecondFi was attacked due to a vulnerability in its transaction signing software. A total of 16.1 million ADA (approximately $2.4 million) across 374 wallets was stolen, and the platform has announced permanent closure. The vulnerability allowed attackers to derive private keys from transaction data visible on-chain. The Cardano network itself was not affected, nor were hardware wallet users. An investigation by Groom Lake, a blockchain intelligence company hired by EMURGO, revealed that the primary attackers were sophisticated and well-funded. Some indications point to North Korea's Lazarus Group, but this has not yet been officially confirmed. SecondFi plans to release a wallet export tool in early August and launch a zero-knowledge recovery portal later in the month. EMURGO has established an asset recovery wallet, with the specific distribution time to be determined.
Cardano ecosystem wallet SecondFi announced that due to a cryptographic defect in its wallet software, approximately 16.1 million ADA (worth around $2.6 million) were stolen. The platform will gradually shut down the SecondFi and Yoroi wallet services. This incident has affected 374 wallets. SecondFi stated that an independent investigation by blockchain intelligence agency Groom Lake identified the attackers as a sophisticated external actor and found indicators potentially linked to North Korea's Lazarus Group, though attribution has not yet been confirmed. SecondFi is developing a recovery tool based on zero-knowledge proofs to help affected users recover assets while limiting the information that needs to be shared. The tool is still being tested and will undergo third-party audits before its planned release in August. SecondFi is also preparing a wallet export feature to allow users to migrate their assets to other services. The platform has not announced a direct compensation plan, nor has it indicated whether it will use its own funds to compensate users.
According to an official post from Midnight Foundation (@midnightfdn), the Wanchain Cardano<>BNB cross-chain bridge suffered a security attack. Currently, multiple major exchanges including KuCoin, Kraken, Binance, Bybit, OKX, and MEXC have responded rapidly, taking preventive measures to restrict the flow of stolen assets, including freezing relevant accounts and addresses, blacklisting the attacker's wallets, and suspending NIGHT token deposit and withdrawal services. The exchanges confirmed that this incident is an isolated third-party bridge vulnerability and is unrelated to the Midnight Network mainnet and the NIGHT asset itself.
the Midnight Foundation has provided an update on the handling of the cross-chain bridge attack event involving Wanchain Cardano and BNB. Multiple exchanges including KuCoin, Kraken, Binance, Bybit, OKX, Gate, and MEXC have coordinated risk control actions, temporarily freezing the involved accounts and associated addresses, adding the hacker wallet to a blacklist, and pausing NIGHT token deposits and withdrawals as needed to curb the transfer and cashing out of stolen assets.The Foundation specifically noted that this security incident is an isolated incident related to a third-party cross-chain bridge, and the Midnight mainnet and native NIGHT assets have not been affected. The project team continues to collaborate with major exchanges and ecosystem partners to advance traceability investigations, reminding the community to rely on official disclosures for information and to be cautious of misinformation.
Odaily, Cardano wallet service provider SecondFi has launched an asset recovery wallet check tool, allowing users to preliminarily check whether their relevant wallets have been affected by the previous security incident.SecondFi stated that the addresses currently displayed in the tool are based on the team's preliminary review data of the security incident and are not final. The list may not be complete and does not represent the final scope of recovery.
: Cardano wallet service provider SecondFi has released an update on the security incident recovery progress, stating that EMURGO has established an asset recovery fund to return assets to users affected by the attack.SecondFi stated that emergency measures have been taken to protect and restore access to some assets. The team is currently discussing appropriate custody mechanisms with Intersect to ensure the safe return of assets to users.Furthermore, SecondFi is collaborating with a Cardano community-led working group to advance the on-chain recovery plan. Due to the recovery plan being more complex than initially expected, the overall recovery time may exceed the previously estimated two weeks.
Odaily, Cardano wallet service provider SecondFi has released an update on the security incident, stating that the team has completed the final balance snapshot of affected user assets. Several rounds of snapshots were continuously recorded during the incident response period to serve as the basis for subsequent asset recovery and reconciliation. SecondFi stated that the engineering and security teams are advancing the asset recovery plan. It is estimated that asset repayment can begin in approximately two weeks — one week allocated for finalizing a viable technical solution and another week for testing and review. The specific timeline may be subject to minor adjustments as progress unfolds. The platform will resume operations only after passing a comprehensive security review. Currently, users only need to submit a support request via the official website's ticketing system, with no additional action required.
SecondFi, a Cardano ecosystem project, stated that the root cause of the recent security incident has been identified as an issue with its in-house Cardano wallet generation software. The team said it has completed on-chain analysis to assess the scope of impact and is currently collaborating with a blockchain security firm for an independent technical assessment. A preliminary estimate of the total impact is approximately 16 million ADA.
: In response to the recent security incident involving Cardano ecosystem project SecondFi, SlowMist founder Cos said on social media that after continuously monitoring the relevant on-chain data, he believes that if the two addresses starting with "addr1q" are both controlled by the attacker, the actual losses for SecondFi users may have exceeded $20 million.Cos stated that based on on-chain behavior analysis, the aforementioned addresses are highly likely related to the attacker, involving stolen assets potentially exceeding 129 million ADA and other tokens.Previously, SecondFi disclosed that this security incident affected approximately 16 million ADA, stating that the issue originated from the web wallet generation software.