Share this article

Here’s How $200M in Crypto Was Drained From Nomad Protocol, According to a Security Expert

Halborn Chief Information Security Officer Steven Walbroehl joined CoinDesk TV’s “First Mover” to discuss how Nomad’s bridge lost $200 million in less than 24 hours.

Updated May 11, 2023, 5:44 p.m. Published Aug 2, 2022, 7:44 p.m.
jwp-player-placeholder

A function irregularity on cross-chain messaging protocol Nomad gave leeway for upward of $200 million to be siphoned off the platform, according to one security expert.

Steven Walbroehl, chief information security officer at blockchain security firm Halborn, told CoinDesk TV that a recent update to Nomad’s smart contracts backfired, prompting transactions on the protocol to be automatically approved.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

The result, although unclear, created a domino-like effect. “Once one person found out about it, it was a crazy mad rush of people who [could] go in there and copy the transaction and say, ‘Hey, I guess I’ll pay myself too, out of the bridge,’” Walbroehl said on CoinDesk TV’s “First Mover” program.

Nomad, which primarily serves as a bridge for users to send and receive tokens among different blockchains, told users Monday evening via a tweet that it was “aware of the incident involving the Nomad token bridge.” By then, the protocol had lost $45 million.

Two hours later, the protocol told users it was “aware of impersonators posing as Nomad and providing fraudulent addresses to collect funds.” By midnight on Monday, the protocol had lost nearly $200 million.

Walbroehl said that a user did not need to have extensive knowledge of such things as Merkle trees (the way data is handled) or the Solidity programming language to engage in the hack. In fact, “all you had to do [was] find a transaction that worked and then replace that address with your own.”

In Nomad’s case, however, all transactions were given the green light, whether or not they were legit. The protocol uses Merkle trees to validate transactions. They are primarily “used to provide blockchain data more securely and efficiently by proving a transaction is valid.”

Walbroehl said that bridges such as Nomad are likely prone to exploits because “most often this is where all the value is stored” – and thus bridges are enticing to hackers.

“You’re going to the vaults to rob the bank, rather than trying to go out and pick everybody's wallet,” he said. “Just go right for the bank.”

The second reason Walbroehl points to is complicated programming, especially when it comes to “two different protocols.”

“If you combine high value with complicated programming and lots of errors happen, that’s where hacks come from,” he said.

Walbroehl believes that the best way to prevent future hacks “is to put defense in depth – do security audits.” In addition, he said that developers should get others to look at their code, as well as testing it on their own.

For users, Walbroehl emphasizes “being aware of the bridges or the bridges that you’re investing in.”

Nomad told CoinDesk that an ongoing investigation is underway and that law enforcement officials have also been notified.

The decentralized finance (DeFi) platform – which recently raised upward of $22 million in a seed round led by big crypto players including Coinbase Ventures and OpenSea – is the latest protocol to face a heavy-handed hack. Back in April, the gaming-focused Ronin Network faced a hack of more than $600 million.

Read more: Crypto Bridge Nomad Drained of Nearly $200M in Exploit

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Turkey's Paribu Buys CoinMENA in $240M Deal, Expanding Into High-Growth Crypto Markets

Yasin Oral, Founder and CEO of Paribu (center) and Dina Sam’an (left) and Talal Tabbaa (right), Co-Founders of CoinMENA (Paribu, modified by CoinDesk)

With the acquisition, Paribu gains regulatory foothold in Bahrain and Dubai and access to the region's fast-growing crypto user base.

What to know:

  • Paribu acquires Bahrain- and Dubai-based CoinMENA for up to $240 million.
  • Deal marks Turkey’s biggest fintech acquisition and first international crypto M&A, the firm said.
  • The move taps into the MENA region’s fast-growing crypto user base and supportive regulatory hubs.