Login
Sign Up
Woofun AI reports that the Wanchain Cardano cross-chain bridge suffered a security breach resulting in the theft of approximately 515 million NIGHT tokens from its treasury. Preliminary investigations identify the root cause as a non-injective signature message encoding issue within the TreasuryCheck validator. The signature message construction directly concatenated 14 variable-length redemption fields without delimiters or length prefixes. This design flaw permitted different combinations of field values to generate identical byte strings, enabling the reuse of the same hash and valid signature.