Svmuu News: Wanchain’s Cardano cross-chain bridge was attacked, resulting in the theft of approximately 515 million NIGHT tokens from the cross-chain bridge’s treasury. Preliminary investigations indicate that the root cause lies in an encoding issue with non-injective signature messages in the TreasuryCheck validator. The signature message was constructed by concatenating 14 variable-length redemption fields without any delimiters or length prefixes, resulting in different combinations of field values producing the same byte string—thereby reusing the same hash and a valid signature.