BlockSec: Wanchain’s Cardano cross-chain bridge was attacked, and about 515 million NIGHT tokens in the bridge vault were stolen

robot
Abstract generation in progress
PANews July 21, citing BlockSec monitoring, the Cardano cross-chain bridge of Wanchain was attacked, with about 515 million NIGHT tokens stolen from the bridge treasury vault. Preliminary investigation indicates the root cause was a non-injective signature message encoding issue in the TreasuryCheck validator. The signature message was constructed by concatenating 14 variable-length redemption fields (folded using AppendByteString) with no separators or length prefixes, allowing different combinations of field values to produce the same byte string, thereby reusing the same hash and a valid signature. BlockSec confirmed the vulnerability by decompiling on-chain Plutus V2 bytecode and decoding the redemption data in the attack transaction. Using Sha3_256(SerialiseData(...)) in place of the current approach, which provides clear CBOR encoding field boundaries, would prevent this type of split-signature hash reuse attack.
ADA2.48%
NIGHT3.18%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned