The Walls Held. So Why Didn't the Losses Go Down?

[Series 1/3] The Walls Held. So Why Didn’t the Losses Go Down?

A special feature on why blockchain security is an ecosystem responsibility, not just a mainnet one. This is part 1 of a 3-part series.

3 September 2026
Ilhun


Over the past decade, the blockchain industry poured enormous resources into securing base layers and consensus protocols. Formal verification, repeated audits, standardized libraries for known bug classes — that investment paid off. Classic smart contract logic flaws like reentrancy and integer overflow have genuinely become rarer.

And yet something odd keeps happening. Q2 2026 set a record: 83 hacks, $755.3 million lost, the most-hacked quarter by incident count in crypto history. The money isn’t leaking from smart contract code anymore. The walls got higher, but the losses simply moved to the gaps between the walls — bridges, wallets, signing procedures, supply chains, the places where it’s genuinely unclear whose job it is to watch.

This series is an attempt to sit with that unclear part. It starts, unavoidably, with an incident closer to home for this community: Cardano’s own ecosystem wasn’t spared.

What the Numbers Actually Say

Security firm Hacken’s Q2 2026 Security & Compliance Report put a number on the shift: 88.3% of that quarter’s losses traced back to compromised keys, signers, or infrastructure — not smart contract bugs. A second figure is even more telling. Of the 1,427 projects Hacken tracked, only 9% had third-party monitoring in place, and just 4% combined monitoring with an active bug bounty and a completed audit.

None of this means audited code is worthless. It means audits, by design, stop at the edge of the code. They don’t cover the firmware build pipeline, the signing approval screen, a bridge validator’s message-encoding logic, or a cloud credential sitting in someone’s CI/CD system. The industry has spent a decade getting very good at defending what any single team fully controls, and comparatively little time figuring out who’s accountable for what sits between teams.

Cardano’s Own Boundary — What the Wanchain Bridge Hack Actually Showed

On July 20, 2026, the Wanchain bridge connecting Cardano and BNB Chain was exploited. The attacker went after a flaw in how the bridge’s TreasuryCheck validator constructed signed messages: fourteen variable-length fields, concatenated with no delimiters. Different field combinations could collapse into an identical byte string. According to BlockSec’s on-chain analysis, a legitimate signature that had authorized a transfer of roughly 3,110 NIGHT tokens on BNB Chain got reused to withdraw over 203 million NIGHT on Cardano — a signature-reuse attack, not a broken cryptographic primitive. Across four transactions in an eight-minute window, roughly 515 million NIGHT tokens (about $9–13 million) drained out, and the token’s price briefly fell more than 30% to an all-time low. (NIGHT is the native token of Midnight, Cardano’s privacy-focused sidechain.)

Both the Midnight Foundation and Wanchain moved quickly to state that Cardano’s Layer 1 and the Midnight protocol itself were untouched. That’s accurate. It’s also not the whole story, because the people who actually absorbed the loss were Cardano ecosystem participants. In a CoinDesk interview, Charles Hoskinson called the exploit “a case of the Mondays” while conceding the broader point: every piece of software is under sustained pressure from AI-accelerated vulnerability discovery, and being “90% resistant” to a threat still means you catch it eventually if exposed long enough. Wanchain offered the exploiter a white-hat deal — return 90% of the funds, keep 10% as a bounty — with an August 6 deadline. As of this writing, no confirmed public outcome of that deadline has been reported.

The lesson isn’t that Wanchain or Cardano did something wrong in isolation. It’s that “the third-party bridge isn’t our jurisdiction” is technically true and practically insufficient. From a user’s vantage point, a bridge is part of the ecosystem they trust. Deciding how rigorously bridge validator logic gets independently audited, and how continuously it gets monitored, isn’t a call for the L1 team alone to make.


Up next in Part 2: we widen the lens to the rest of the industry — the Coldcard hardware wallet incident, the Bybit hack, and repeated IBC/interchain vulnerabilities — to show this isn’t a Cardano-specific problem. Curious to hear this community’s take in the meantime: where do you think the line should sit between an L1 team’s responsibility and a third-party integration’s?

Key Terms

  • eUTXO (Extended Unspent Transaction Output): Cardano’s accounting model, an extension of Bitcoin’s UTXO model designed to support smart contracts.
  • Bridge: Third-party infrastructure that lets assets move between different blockchains.
  • White-hat deal/bounty: A negotiated arrangement where an attacker returns most of the stolen funds in exchange for keeping a portion as a reward, instead of facing pursuit.
  • Midnight / NIGHT: Midnight is Cardano’s privacy-focused partner chain; NIGHT is its native token.

Sources: Hacken, BlockSec (via TokenPost), CoinDesk, CryptoTimes.

security

1 Like