2026-07-21
Getting Bridges back on Track
- A whiteboard lecture prompted by the OneChain Cardano to Binance Smart Chain bridge hack that stole about 500 million NIGHT, explaining why bridge hacks keep happening.
- He walks through how a lock and mint bridge works, its four attack surfaces, and why the stolen BC-NIGHT is a synthetic peg while the underlying CNIGHT and Midnight were never hacked.
- He presents ZK bridges with verifier contracts on both sides as trustless, and multimodality (ZK plus threshold signatures) so a flaw costs liveness, not safety.
- He argues Midnight solves the bridge, wallet, white hat, and identity problems at once, enabling a blockchain-wide warning pub-sub, circuit breakers, and wallet insurance.
- The pitch: crypto only becomes real when it matches the legacy system's consumer protections without a financial panopticon, the web 2.5 middle ground.
47 entries
A thief stole funds on the OneChain Cardano to Binance Smart Chain bridge, and makes a whiteboard video on the root cause since bridge hacks are the top loser of funds over 36 months.
It is ironic that Midnight was built to solve exactly these problems, yet the hack hit a Midnight asset in the Cardano ecosystem, and Midnight is the solution.
He mentioned the problem to Aggelos, whose research team had just written the first rigorous universal composition and model-checking formalization of blockchain bridges, a 43 page IACR paper.
The paper mathematically defines any bridge with small step semantics and covers native consensus, certificate, ZK, and threshold signature bridge types.
A bridge does far more than move assets: he authored a document listing 42 things you can state about Cardano and 52 about Midnight, from UTXO membership to governance and shielded tokens.
Sets up Bob on Cardano and Alice on Binance Smart Chain, with CNIGHT issued by a smart contract, fully decentralized as a Cardano native asset that cannot be rolled back.
Binance wanted NIGHT on Binance Smart Chain, so the years-old OneChain bridge, a Catalyst-funded Chinese bridge, moved Cardano native tokens to BSC.
The lock and mint flow: you lock CNIGHT, get a receipt bound to a redeemer address, the bridge injects it into BSC and mints wrapped BC-NIGHT pegged one to one.
The reverse: Alice destroys BC-NIGHT for a receipt bound to a Cardano address, and the bridge unlocks the corresponding CNIGHT, watching both chains via full nodes.
The bridge is a guardian that replays each chain to verify assets are real, and distinguishes custodial pools held by a trusted third party from non-custodial where you control both sides, as Bitcoin DeFi mirroring does.
Features like liquidity pools and custody accounts speed bridges up but are where attack vectors live, alongside multisig signatures and unlock logic rules.
Lists the four attack surfaces that must all cooperate: the Cardano Plutus contract, the BSC Solidity contract, the off-chain BSC infra, and the off-chain Cardano infra.
Upgradability adds admin keys to move from contract v1 to v2, and compromising those keys lets an attacker, evil Jim, rewrite the contract to send everything to himself.
Says where a hack occurs tells you its nature: public on-chain code any black hat can exploit, or private off-chain code usually compromised by an insider threat.
The paper covers every style exhaustively, and introduces hybrid apps where a Cardano smart contract only executes when Binance reaches a certain block height.
The Cardano contract cannot know Binance's state itself, so it needs a root of trust, an oracle, telling it the event occurred.
The trigger can come from a trusted third party, a federated multisig, a bespoke threshold signature, or the heaviest option, zero knowledge, which is where Midnight lives.
A ZK bridge: Bob generates a proof bound to a BSC redeem address, and a ZK verifier contract on BSC checks it is unforgeable and mints BC-NIGHT, with no bridge operator.
Midnight was built as a generic, fast, programmable ZK system so you can build embedding contracts loaded with facts, leaving only upgradability as the root of trust.
You can do perfect mirroring instead of operator-watched escrow, keeping verification contracts current by injecting state as hard forks change semantics, like Ethereum's proof of stake move or Prow to Laos.
The holy grail multimodality bridge combining ZK with a bespoke threshold signature scheme, allowing a transaction only when both agree.
Framed as liveness versus safety, a flaw in the ZK client side or the threshold server side costs only liveness, never safety, so no one can ever steal your money.
Admin updates use a trusted execution environment with MPC or Shamir secret sharing, making an m of n key infrastructure effectively unhackable barring pervasive insider threat.
Says when an attack occurs you first need a warning system to alert other operators, DeFi apps, and especially lenders, since attackers flood DEXes and lend against stablecoins to launder.
The asymmetry: if BC-NIGHT is stolen the operator can break the one to one peg and make it non-redeemable, but stolen CNIGHT is like stealing ADA and cannot be clawed back.
Early detection needs a blockchain-wide pub-sub system he has wanted for years but was blocked from building, now a high priority for Cardano in 2027 after Laos, his eighth attempt.
DEXes, DeFi, wallets, and exchanges could subscribe to operator or Foundation channels and flood the network with a warning so circuit breakers pull liquidity within seconds.
USDCX helps because unlike pure USDC it cannot go straight to Tornado Cash, it must route through Circle, so that laundering path can be cut off.
Introduces the white hat response: embedding a white hat license in a wallet at creation, a checkbox authorizing recovery of your funds during an active attack.
The two blockers are identity and non-repudiation, since non-custodial wallets have no KYC so no way to know who owns them or that they legally authorized the white hat.
A first-class identity with selective disclosure lets you privately link a wallet to an identity, so an event can later prove ownership and the signed white hat license via a ZK proof without decrypting anything.
The identity credential lives in a trusted execution environment on your phone via the Midnight passport, separate from the wallet, so a compromised wallet does not compromise the credential, like a Ledger.
Third parties each offer one piece, wallet recovery or identity or a bridge, but Midnight combines them into one programmable TypeScript toolbox via Compact.
Midnight solving the bridge problem also solves the wallet, white hat, and identity problems that underpin the industry, and crypto must grow up and be accountable adults.
The legacy system has laws, consumer protections, courts, dispute resolution, asset freezing, and law enforcement, and crypto's edge is you are in control, not a third party.
Legacy banks reverse stolen transactions daily, a conversation crypto users never get to have, so mass adoption requires matching that safety without a financial panopticon.
Calls the middle ground web 2.5, the best of both worlds and the industry's main growth area, XRP, BNB, USDC, Tether, and Canton, needing privacy, smart compliance, and abstraction to link both worlds.
Midnight survived the theft of 500 million NIGHT, about half the size of the Ethereum crowd sale, while Midnight itself and the CNIGHT contract were not hacked, only the third party bridge.
Next generation bridges need multimodality with a management and a ZK layer checking each other, plus a warning system, a white hat license, and the Midnight passport, or crypto stays buyer beware.
Crypto today is an unwinnable zombie survival game, and the winnable one adds insurance, early detection, dispute resolution, and consumer protections as choices, without removing non-custodial wallets, which are strengthened.
Europe's MiCA and the US political left want crypto only in custodial environments, using daily hacks and North Korea as the argument, so adding consumer protections to non-custodial defeats the ban.
Wallet and bridge insurance is a trillion dollar RWA with yield, and he met the Bermuda Monetary Authority who want to figure out how to underwrite it.
You bind a wallet to an identity and an insurance policy and choose by checkbox whether it is recoverable, insured, or white-hat protected, or stay a buyer-beware legacy Bitcoin account.
The third option puts you in the driver's seat with checks and balances and marketplaces, not Mad Max nor an untrusted custodian, a principal reason Midnight was built.
The hack is the single biggest advertisement for Midnight, since hacks only worsen as AI finds vulnerabilities, citing recent Linux kernel bugs and an 11 hour NSA breach.
A correctly implemented digital signature or zero knowledge proof is extremely hard to break, so math beats AI, and layering multimodality is the high assurance realm Cardano lives in.
Closes by praising Aggelos and team's rigorous paper, which uniquely did both a universal composition and a Quint and TLA model-checking formalization, with Microsoft Research among the interdisciplinary co-authors.