Wanchain @wanchain_org Cardano bridge was reportedly being attacked, with ~515M $NIGHT drained from the bridge Treasury.
Our initial investigation suggests that the root cause seems to be a non-injective signed-message encoding in the TreasuryCheck validator. The signed message is built by raw-concatenating 14 variable-length redeemer fields (via `AppendByteString` fold) without delimiters or length prefixes. Different field-value tuples can produce the same byte string — and therefore the same hash and a valid signature reuse.
We verified this by decompiling the on-chain Plutus V2 bytecode (pic 1) and decoding the attack redeemer from the exploit TX (pic 2).
The same on-chain bytecode also contains a `SerialiseData` builtin — but it is only used on the output-datum matching path, not in the signature-hash construction. Using `Sha3_256(SerialiseData(...))` instead would have provided unambiguous CBOR-encoded field boundaries, preventing this class of field-splitting signature reuse.
Attack TX: https://t.co/hmmPlgmfma
🚨 DeFiTuna on #Solana was exploited for 569,601 USDC after a fixed-point value below one raw unit was truncated to zero and is_healthy() treated the zero-valued, debt-bearing position as healthy.
💰 Impact: The lending vault sent 570,000 USDC; 399 USDC was retained as protocol fee and the remaining 569,601 USDC was routed into an attacker-created TUNA/USDC pool. Two malicious limit orders immediately withdrew 568,560.966462 USDC; the remaining 1,040.033538 USDC stayed in the fake pool vault at that point.
�� Time: 2026-07-16 05:48:12 UTC, Solana slot 433214256
🔎 Root cause: compute_total_and_debt() multiplied 494 raw TUNA units by the reference price and converted the positive fixed-point result with to_num::<u64>(), discarding the fractional part and producing total = 0. is_healthy() then returned true solely because total == 0, without requiring debt == 0.
🧭 Attack trace:
The attackers created a nearly empty TUNA/USDC Fusion pool and placed two limit orders containing only 0.000526 TUNA each at an extreme tick.
They opened a DeFiTuna spot position with zero collateral and borrowed 570,000 USDC.
After the 399 USDC fee, an attacker-controlled Jupiter route sent 569,601 USDC into the prepared pool.
The pool returned only 0.000494 TUNA, worth less than one raw USDC unit at DeFiTuna's reference price.
Integer conversion rounded the position's total assets to zero; the total == 0 branch marked the indebted position healthy.
The two attacker-controlled limit orders withdrew 284,280.483231 USDC each.
📌 Key addresses:
Primary signer: 7hiHL8AgDuLNVDQLfN3GHdLAEeCN1F7uz6nSANRvFJst
DeFiTuna program: tuna4uSQZncNeeiAMKbstuxA9CUkHH6HmC64wgmnogD
Fusion program: fUSioN9YKKSa3CUC2YUc4tPkHJ5Y6XW1yz8y6F7qWz9
Fake pool: 917DKTphW3rhBG5gsJpwKsNGisNV2dx74uUFd8HBEjtg
Lending-vault state/authority: D76dDcSU5HnAGqVEZCDLyGgLpTp4xZuqeZyVDtUdDv55
Damaged USDC token vault: 4iTbtBmr4fXpkUD4kTW9pujvXbCT3AkWya6h3dbNP7a6
Fake-pool USDC vault: GpKYG4iFoty4mnhfKfyLCkQ26Mm2NRFcezmDmzaBQb14
🧾 Txs:
Borrow and swap: https://t.co/yscbw9RlxF
First withdrawal: https://t.co/FS8yyzwkZB
Second withdrawal: https://t.co/WM3MSteH6m
🛡️ Takeaway: A zero asset valuation is not an empty position when debt is nonzero. Solvency checks must round conservatively, preserve fixed-point precision through the comparison, reject zero-collateral debt, and require debt == 0 before treating total == 0 as healthy.
Powered by #DarkNavy Web3 AI Agent
🚨 EXPLOIT - TeleSwap (BTC bridge) was exploited on Jul 15 for ~10.33 BTC (~$735K) - still undisclosed 5 days later.
Its BTC hot wallet sent the stolen funds straight to the attacker, then went quiet (balance now 0)
Theft addr (now empty):
https://t.co/drvfc06x8C