BlockBeats News, July 21st, according to BlockSec Phalcon monitoring, Wanchain's Cardano cross-chain bridge was attacked, with approximately 515 million NIGHT tokens stolen from the bridge Treasury.
BlockSec's preliminary analysis believes that the root cause of the vulnerability lies in the TreasuryCheck validator using a non-injective encoding method for the signature message: directly concatenating 14 variable-length fields to generate the message to be signed, without using delimiters or length prefixes, resulting in different field combinations that may produce the same byte sequence, allowing the reuse of a legitimate signature to complete the attack.
