Crypto Fraud Watch: A $10M Bridge Exploit, a Cold-Wallet Breach, and a Solana Flash-Loan Attack

The last two days delivered a stark reminder that the weakest points in crypto are rarely the blockchains themselves, but the bridges, custodians, and lending contracts built around them. Three separate security failures drained roughly $12 million combined, hit privacy tokens, exchange partners, and DeFi liquidity alike. Here is what happened and what it means for anyone holding, trading, or building with digital assets.

A $10 Million Bridge Exploit Sinks the NIGHT Token

On July 21, 2026, security firm BlockSec's Phalcon monitor flagged an exploit of Wanchain's bridge connecting Cardano to the BNB Chain. An attacker drained roughly 515.2 million NIGHT tokens, worth about $10 million, in just four transactions over an eight-minute window. According to BlockSec's initial analysis, the root cause was a signature-reuse flaw: the bridge validator built its signed messages by raw-concatenating variable-length fields without proper delimiters, letting a signature that originally authorized about 3,110 tokens be replayed to extract more than 203 million. NIGHT, the native token of the privacy-focused Midnight network, fell 30 to 40 percent intraday to a new all-time low. Wanchain paused the bridge and pledged a full investigation.

The legal takeaway is familiar but worth repeating: cross-chain bridges concentrate enormous value behind smart-contract logic that few users ever audit. When that logic fails, victims are scattered across jurisdictions and the responsible operator may be an offshore or pseudonymous entity. Midnight's team was quick to stress that its underlying protocol was not compromised, a distinction that matters legally when apportioning liability between a token issuer and a third-party bridge provider.

Zilliqa's Cold-Wallet Breach Raises Custody Questions

Also on July 20, Zilliqa disclosed that ZIL tokens had been stolen from a cold wallet belonging to one of its exchange partners. Cold storage is marketed as the gold standard of security precisely because the keys are kept offline, so a breach of one strikes at a core assumption many investors rely on. ZIL dropped roughly 15 percent before partially recovering, and Zilliqa asked exchanges to pause ZIL deposits and withdrawals to stop the stolen funds from being liquidated.

For investors and businesses, the incident is a reminder that "cold wallet" is not a guarantee, and that custody risk often lives with a partner you never chose. Whether a user can recover losses may hinge on the custody agreement's terms, the exchange's insurance, and which jurisdiction's consumer-protection rules apply, questions best answered before funds are ever deposited, not after they vanish.

A Solana Flash-Loan Attack Hits Allbridge Again

Rounding out the stretch, Allbridge Core was hit by a roughly $1.65 million flash-loan exploit on Solana on July 20, the protocol's second such incident since 2023. Flash loans let an attacker borrow and repay enormous sums within a single transaction, using the temporary capital to manipulate a protocol's internal pricing or accounting before anyone can react. That a project could be exploited twice by the same class of attack underscores how difficult, and how legally consequential, remediation can be.

Repeat exploits raise the stakes for operators. A second failure invites scrutiny over whether a project met a reasonable standard of care, disclosed known risks to users, and honored any prior commitments to harden its code. Those are exactly the questions regulators and plaintiffs' attorneys ask when deciding whether a loss was simple misfortune or actionable negligence.

How to Protect Yourself

The through-line across all three incidents is dependency risk: you can hold your own keys responsibly and still be exposed through a bridge, an exchange partner, or a lending protocol you interact with only indirectly. Limit funds parked in cross-chain bridges to what you actively need, favor assets and platforms with published, independently audited code, and treat any protocol that has been exploited before as higher risk regardless of its assurances. When a project announces a breach and asks exchanges to pause transfers, act immediately: move what you can to storage you control and document your holdings and transaction history before prices and access shift.

If you have already lost funds, legal recourse depends on speed and records. Preserve wallet addresses, transaction hashes, screenshots, and any communications with the platform, because on-chain tracing and asset-freezing are most effective early. Depending on the facts, victims may have claims against operators, custodians, or exchanges, and may be able to work with law enforcement and blockchain-forensics firms to follow the money. An attorney who understands both the technology and the relevant regulatory framework can help you assess whether recovery is realistic and what steps preserve your rights.

At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud โ€” whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.

Disclaimer

This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.

Next
Next

Crypto Fraud Watch: $1.3 Billion Stolen in Six Months, a Locked-Vault Drain, and Wall Street Buys In Anyway