Two Cardano-linked hacks in a week — why 'the blockchain is fine' isn't the whole story
Two separate security failures hit projects built around the Cardano blockchain this week, and together they show an unc…
Two separate security failures hit projects built around the Cardano blockchain this week, and together they show an uncomfortable truth for beginners: the blockchain itself can keep running perfectly while people still lose money on the services around it. In one case an attacker drained roughly 515 million NIGHT tokens from a cross-chain bridge; in another, a wallet provider called SecondFi said it will shut down after about $2.6 million in ADA was stolen.
The bigger incident involved a "bridge." A bridge is a tool that lets tokens move from one blockchain to another — here, moving the NIGHT token between Cardano and BNB Chain. On July 20, an attacker removed about 515 million NIGHT from the Cardano-side reserve backing the bridge, which was operated by a third party called Wanchain. Security firm BlockSec said its early analysis pointed to a flaw that may have let an old, valid signature be reused with new transaction data, though it stressed the investigation is preliminary. NIGHT briefly fell more than 30% to a record low.
Importantly, the Midnight Foundation said its own protocol, validators and core network were not affected, and the NIGHT contract on Cardano kept working normally. In other words, the chain was fine; the bridge was not. Cardano founder Charles Hoskinson put it bluntly: "Bridges are the most vulnerable of all of these attacks in the cryptocurrency space." Attackers have stolen more than $2 billion from bridges over the years, because a bridge has to coordinate trust across two separate networks — and that seam is where things tend to break.
The second case was a wallet flaw. SecondFi said attackers stole about 16.1 million ADA (roughly $2.6 million) because of a cryptographic weakness in its wallet software, affecting 374 wallets. An outside investigation reportedly found signs possibly linked to North Korea's Lazarus hacking group, though nothing has been confirmed. The company is now winding down and says recovery tools are still being built, with no direct reimbursement announced.
There was a small silver lining on the bridge hack: major exchanges including Binance, Kraken and OKX moved to freeze and blacklist wallets tied to the theft, narrowing where the attacker could cash out. That kind of coordinated response can limit damage after the fact, but it is no substitute for the funds never being stolen in the first place.
The lesson isn't "Cardano is unsafe." It is that in crypto, the riskiest part is often not the blockchain but the extra layers bolted onto it — bridges, third-party wallets, and other services. As a beginner, be extra careful before moving tokens across a bridge or trusting a newer wallet with large amounts. Ask who operates it, whether it has been audited, and whether you could survive the loss if that one piece failed.