Share this article

Crypto Bridge Nomad Drained of Nearly $200M in Exploit

The exploit calls the security of cross-chain token bridges into question once again.

Updated May 11, 2023, 3:56 p.m. Published Aug 2, 2022, 3:35 a.m.
jwp-player-placeholder

The cross-chain token bridge Nomad was exploited Monday, with attackers draining the protocol of virtually all of its funds. The total value of cryptocurrency lost to the attack totaled near $200 million.

Nomad, like other cross-chain bridges, allows users to send and receive tokens between different blockchains. Monday’s attack is the latest in a string of highly publicized incidents which have drawn the security of cross-chain bridges into question.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

The Nomad team acknowledged the exploit in a statement to CoinDesk. "An investigation is ongoing and leading firms for blockchain intelligence and forensics have been retained," the team said. "We have notified law enforcement and are working around the clock to address the situation and provide timely updates. Our goal is to identify the accounts involved and to trace and recover the funds."

What happened?

Bridges typically work by locking up tokens in a smart contract on one chain and then reissuing those tokens in “wrapped” form on another chain.

If the smart contract where tokens are initially deposited gets sabotaged – as happened in Nomad’s case – the wrapped tokens no longer have any backing, which can render them worthless.

On Twitter, @samczsun, a researcher at crypto investment firm Paradigm, explained that a recent update to one of Nomad’s smart contracts made it easy for users to spoof transactions. This meant users were able to withdraw money from the Nomad bridge that didn’t actually belong to them.

Unlike some bridge attacks, where a single culprit is behind the entire exploit, the Nomad attack was a free for all.

“... [Y]ou didn't need to know about Solidity or Merkle Trees or anything like that. All you had to do was find a transaction that worked, find/replace the other person's address with yours, and then re-broadcast it,” @samczsun explained.

Nomad: A 'secure' alternative?

Bridge attacks have become more frequent in recent months as crypto users have demonstrated an increased appetite for swapping assets between different blockchains.

While cross-chain bridges have made it possible for upstart blockchains to proliferate, bridge failures can be devastating for smaller chains that rely on them for a large amount of their total liquidity.

Evmos, one of the newer blockchains serviced by Nomad, tweeted that it would be “brainstorming community solutions” to the Nomad attack given that it “significantly impacts initial Evmos [total value locked].”

The largest decentralized finance (DeFi) attack in history, April’s Ronin bridge attack, saw over $600 million worth of crypto siphoned out of the bridge that powers the blockchain-based game Axie Infinity.

Just a few months before that, over $300 million was drained from the Wormhole bridge, wreaking havoc across the Solana blockchain community and the wider decentralized finance ecosystem.

Nomad sold investors on the vision that it would be fundamentally more secure than alternative platforms.

Just last week, it revealed that crypto heavyweights Coinbase Ventures and OpenSea were among those that participated in an April seed round that valued the company at $225 million.

This is a developing story. Check back for updates.

UPDATE (Aug. 2, 04:37 UTC): Adds statement from Nomad.

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Peter Thiel and Galaxy-backed Citrea wants to turn idle bitcoin into a high-speed bank account

A photo of Citrea's four co-creators (Citrea)

Founders Fund and Galaxy-backed Citrea is aiming to unlock Bitcoin-denominated credit markets with a new mainnet and a Treasury-backed stablecoin designed for USD settlement.

What to know:

  • Citrea has debuted its mainnet, enabling Bitcoin-backed lending, trading and structured products directly tied to the Bitcoin network.
  • The platform introduced ctUSD, a Treasury-backed stablecoin issued by MoonPay and designed to align with forthcoming U.S. stablecoin rules.
  • Citrea says the rollout aims to mobilize idle BTC and provide an institutional-grade settlement layer for Bitcoin-based capital markets.