Wanchain has given the attacker behind last week’s bridge exploit until 12:00 UTC on August 6 to voluntarily return the stolen assets, offering a limited-time settlement before escalating recovery efforts through law enforcement and public bounty programs.

The ultimatum follows one of the largest bridge exploits of the year, in which approximately 515 million NIGHT tokens were drained from Wanchain’s Cardano-to-BNB Chain bridge. At the time of the attack, the stolen assets were valued at roughly $13 million, although their market value fluctuated sharply as the attacker sold a significant portion of the tokens into decentralized exchanges.

In an on-chain message and accompanying public statement, Wanchain offered the exploiter an opportunity to return the remaining assets in exchange for a negotiated resolution. If the funds are not returned by 12:00 UTC on August 6, the company said it intends to pursue all available legal remedies while expanding efforts to identify the attacker.

The approach mirrors a strategy increasingly adopted across decentralized finance following major exploits. Rather than immediately pursuing litigation, protocols frequently offer attackers a “white hat” settlement that allows them to retain a percentage of the stolen assets as a bounty in exchange for returning the remainder.

If negotiations fail, those offers are typically withdrawn and replaced by larger rewards for information leading to the hacker’s identification and prosecution.

Bridge Exploit Triggered Sharp NIGHT Sell-Off

The attack targeted Wanchain’s cross-chain bridge connecting Cardano and BNB Chain rather than the Midnight blockchain itself.

Blockchain security researchers said the attacker drained roughly 515 million bridged NIGHT tokens, representing approximately 97% of the bridge’s reserves. The funds were subsequently transferred across multiple wallets before large quantities were sold on Cardano-based decentralized exchanges, driving NIGHT to an all-time low.

The Midnight Foundation emphasized that its blockchain, validator network and consensus mechanism were not compromised. Instead, the incident was confined to the third-party bridge infrastructure responsible for transferring wrapped versions of NIGHT between blockchains.

Preliminary technical analysis from security researchers suggested the exploit may have stemmed from a flaw in the bridge’s message validation process, although Wanchain has not yet published its full postmortem.

The affected bridge remains suspended while investigators continue examining the incident and coordinating with blockchain analytics firms.

Recovery Efforts Intensify

The August 6 deadline represents a critical point in Wanchain’s recovery strategy.

Should the attacker fail to cooperate, investigators are expected to expand blockchain tracing efforts while working with centralized exchanges, analytics providers and law enforcement agencies to monitor any movement of the stolen assets.

Although decentralized finance protocols cannot reverse blockchain transactions, they increasingly rely on forensic analysis to identify attackers when stolen assets eventually interact with regulated financial infrastructure.

The incident also highlights the continuing security challenges facing cross-chain bridges, which remain among the cryptocurrency industry’s most frequently targeted pieces of infrastructure because they secure large pools of locked assets across multiple blockchain ecosystems.

For token holders, the deadline offers one remaining opportunity for an amicable resolution. If no agreement is reached by 12:00 UTC on August 6, the dispute is likely to shift from private negotiations toward public enforcement efforts, extending what has already become one of 2026’s most significant bridge security incidents.