Home arrow Article arrow Article Detail

Crypto token bridge Nomad drained $190M in funds in security exploit

Profile Image

Joyashree Dey Follow


Aug, 05 2022

Aug, 05 2022

likes 0 | comments 0

Article Image

The Nomad token bridge has experienced a security exploit that has allowed hackers to systematically drain roughly $190.7 million of the bridge’s funds over a long series of transactions, with only $651.54 left remaining in the wallet.

Since one of the most extensive hacks of Axie Infinity's Ronin Bridge Sidechain in March, Nomad’s funds stolen were denominated in Ethereum, USDC, DAI, FXS, and CQT. 

"We are aware of the incident involving the Nomad token bridge. We are currently investigating and will provide updates when we have them," Nomad tweeted Monday afternoon. 

Nomad gave no further details yet. In between some people have pointed to a configuration error in a smart contract that Nomad uses to handle messages as the cause, permitting millions to be drained from Nomad's liquidity pool.  

"It all started when @officer_cia shared @spreekaway's tweet in the ETHSecurity Telegram channel," Sam Sun, a researcher at crypto investment firm Paradigm, tweeted. "Although I had no idea what was going on at the time, just the sheer volume of assets leaving the bridge was clearly a bad sign." 

"It turns out that during a routine upgrade," Sun continued. "The Nomad team initialized the trusted root to be 0x00. To be clear, using zero values as initialization values is a common practice. Unfortunately, in this case, it had a tiny side effect of auto-proving every message." 

The Nomad Bridge helps users to move digital assets between various blockchains, including Avalanche (AVAX), Ethereum (ETH), Evmos (EVMOS), Milkomeda C1, and Moonbeam (GLMR). 

likes 0 Likes | comments 0 Comments

Profile Image

Joyashree Dey

CBW - External Analyst


Disclaimer: The information is for informational purposes only.​ This advertisement does not constitute financial advice or any other advice. You should consult with a financial professional to determine what may be best for your individual needs. None of the information and/or content available through this advertisement is intended as an offer or solicitation of an offer to buy or sell, or as a recommendation, endorsement, or sponsorship of any company, financial product, security or commodity. To the maximum extent permitted by law, we disclaim any and all liability in the event any information, commentary, analysis, opinions, advice and/or recommendations prove to be inaccurate, incomplete or unreliable or result in any investment or other losses. In Making the investment decision, investors must rely on their own examination of the issuer and the terms of the offerings, including the merits and risks involved. Investments are speculative, illiquid, and involve a high degree of risk , including the possible loss of investment.