Hackers drain nearly the entire $190.7M in crypto from the Nomad token bridge, which raised an April 2022 seed from Coinbase, OpenSea, and five other companies
Hundreds of potential exploiters appear to have drained all of the bridge's $190 million in TVL in just a matter of hours. — 57 Total views
Cointelegraph Brian Newar
Context & Ripple Effects
Nomad's loss follows the Ronin Network breach, which showed that a bridge supporting a major crypto application could become a concentrated target. Nomad's April seed backing from Coinbase, OpenSea, and other companies ties the incident to prominent ecosystem investors as well as bridge users.
The subsequent tally of $2B stolen across 13 bridge hacks places Nomad within a growing series rather than an isolated failure. Earlier coverage had already counted more than $1B lost in bridge-related exploits over little more than a year.
First-order effects
- Nomad users face the near-total loss of the assets held in the bridge, while Nomad must address an exploit that emptied its reported $190.7M in TVL within hours.
- Coinbase, OpenSea, and Nomad's other seed backers are immediately associated with a compromised piece of crypto infrastructure they funded only months earlier.
Second-order effects
- Other cross-chain bridge operators face heightened pressure to demonstrate safeguards as the related coverage records repeated large-scale bridge losses, including Ronin and Nomad.
- Bridge users and capital providers have stronger reason to treat TVL as concentrated security exposure, not simply a measure of adoption, raising the cost of trust for bridge operators.
Third-order effects
- If bridge exploits continue to account for a disproportionate share of crypto theft, cross-chain connectivity becomes a structural legitimacy and security constraint for the broader ecosystem.
- The pattern favors crypto infrastructure whose security practices can withstand scrutiny, while bridges that cannot establish that confidence risk losing users and locked assets.
The trend: Cross-chain bridges are becoming a central weak point in crypto, with repeated losses turning interoperability into a test of ecosystem trust.
Related: Crypto legitimacy gap · Nomad · Bridge hacks reach $2B in 2022 · Ronin Network hack
Related Coverage
- Nomad Bridge Drained of Nearly $200M in Exploit CoinDesk · Sam Kessler
- Nomad Token Bridge Raided for $190M in ‘Frenzied Free-For-All’ Blockworks · David Canellis
- Hackers abuse ‘chaotic’ Nomad exploit to drain almost $200M in crypto TechCrunch · Carly Page
- Crypto Bridge Nomad Exploited for $190M in ‘Frenzied Free-for-All’ Decrypt · Jason Nelson
- Crypto token bridge Nomad completely drained as users turn on company TechRadar
- Here's how $190 Million were stolen in the First-Ever Decentralised Robbery The Coin Crunch · Naimish Sanghvi
- Nomad Bridge Hack: Here's the Full Account of How Exploit Happened Coinspeaker · Mayowa Adebajo
- Binance Akan Rilis Soulbound Token (SBT) yang Digagas Vitalik Buterin Sumbu Botol · Ahmad Rifai
- Nomad Lost Nearly $190m TVL in “Decentralized Robbery” Blockchain News · Mervyn Kwan
- Nomad bridge drained of $190M after hundreds of addresses copy hacker's code CryptoSlate · Oluwapelumi Adejumo
- Breaking: Over 41 Addresses Identified In $190 Million Nomad Hack CoinGape · Ashish Kumar
- Crypto Bridge Nomad Drained of Nearly $200 Million in Exploit Bloomberg · Sidhartha Shukla
- $190M Stolen From Nomad Bridge in “Frenzied Free-for-All” Hack Crypto Briefing · Chris Williams
- Nomad Hacked, $45M Stolen So Far: Report CoinDesk · Greg Ahlstrand
Discussion
-
@nomadxyz_
@nomadxyz_
on x
We are aware of the incident involving the Nomad token bridge. We are currently investigating and will provide updates when we have them.
-
@0xfoobar
@0xfoobar
on x
Nomad bridge getting actively hacked. WETH and WBTC being taken out in million-dollar increments. Withdraw all funds if you can, still $126m remaining in the contract that's likely at risk https://twitter.com/...
-
@nomadxyz_
@nomadxyz_
on x
We're aware of impersonators posing as Nomad and providing fraudulent addresses to collect funds. We aren't yet providing instructions to return bridge funds. Disregard comms from all channels other than Nomad's official channel: @nomadxyz_
-
@fatmanterra
Fat Man
on x
Messages popping up in public Discord servers of random people grabbing $3K-$20K from the Nomad bridge - all one had to do was copy the first hacker's transaction and change the address, then hit send through Etherscan. In true crypto fashion - the first decentralized robbery. ht…
-
@samczsun
@samczsun
on x
10/ It turns out that during a routine upgrade, the Nomad team initialized the trusted root to be 0x00. To be clear, using zero values as initialization values is a common practice. Unfortunately, in this case it had a tiny side effect of auto-proving every message https://twitte…
-
@xiliangchen
Bryan Chen
on x
1/ Some thoughts about smart contract security. What went wrong? Can we do better? How to do better? TLDR; we need better redundancy.
-
@mg_486662
@mg_486662
on x
1/ Nomad's bridge got owned in a similar manner to Qubit's QBridge. An insecure configuration of the bridge caused a specific path to allow any transaction sent. The error is inside the Replica's “process” function.
-
@0xfoobar
@0xfoobar
on x
Sadly, the answer can be found directly in the Nomad audit report. Reminiscent of the Rune hack where the vulnerable function had a code comment above it explaining how to exploit it. Audit report here: https://github.com/... https://twitter.com/...
-
@paradigmeng420
@paradigmeng420
on x
The Nomad bridge was just exploited for 165m Currently, the details of the hack are unknown and this is not a post-mortem. However, here are some details about the hack 👇 🧵 (1/12)
-
@notifi_xyz
@notifi_xyz
on x
im returning this money, fbi pls calm down. no i didnt plan to steal it and yes i know this address is doxed https://www.notifi.xyz/...
-
@mudit__gupta
Mudit Gupta
on x
Woke up to another bridge hack. Good morning crypto twitter 🫡 This time, Nomad got rekt for around 190m. Some of it was whitehacked though. The attacker could've have stolen everything in a single transaction but they didn't and got front run. https://twitter.com/...
-
@moonbeamnetwork
@moonbeamnetwork
on x
1/ Important Notice: The Moonbeam Network has gone into Maintenance Mode in order to investigate a security incident with a smart contract deployed on the network.
-
@chainlinkgod
@chainlinkgod
on x
Not only are all the people who held Nomad bridged tokens now completely rekt, but so are the chains that used Nomad as their canonical token bridge The contagion effects are real, absolutely brutal https://twitter.com/...
-
@moonbeamnetwork
@moonbeamnetwork
on x
The Moonbeam Network Maintenance Mode has ended following an investigation that found no evidence that the recent security incident was related to the Moonbeam codebase. The chain has been restored to full functionality and is now operating as usual.
-
@0xfoobar
@0xfoobar
on x
TL;DR - a poor operational strategy led to bad merkle root initialization which led to every message being proven valid by default Rough timing as the Nomad team raised a $22 million round several months ago and recently announced significant backing https://twitter.com/...
-
@samczsun
@samczsun
on x
12/ tl;dr a routine upgrade marked the zero hash as a valid root, which had the effect of allowing messages to be spoofed on Nomad. Attackers abused this to copy/paste transactions and quickly drained the bridge in a frenzied free-for-all
-
@moonbeamnetwork
@moonbeamnetwork
on x
1/ Earlier today, there was a security incident that impacted the @nomadxyz_ bridges to Moonbeam. Nearly all the assets in Nomad's Ethereum Mainnet smart contract have been drained. We have found no evidence that the recent security incident was related to the Moonbeam codebase.
-
@andysayler
Andy Sayler
on x
The best thing about web3 is that it comes with built-in bug bounties. 😂 https://twitter.com/...
-
@0xmisaka
@0xmisaka
on x
Nomad is definitely one of the best team in crypto This hack simply shows how hard it is to create a secure bridge infra
-
@dzack23
@dzack23
on x
Front-running all of your bad nomad takes: 1. “This is why trustless bridges are better” The trust model wasn't compromised. 2. “This is why multi chain = bad.” There was nothing bridge-specific about the exploit. 3. “Nomad team = bad” Smart, good people make mistakes.
-
@cl207
@cl207
on x
today, im joining the nomad team as hack recovery manager pls dm me to refund before cat shows up with a mig29
-
@quantstamp
@quantstamp
on x
Our team has investigated the Nomad incident and here's a summary of what we found 👇
-
@nassyweazy
Nass
on x
The Security team at @a16z Crypto has investigated and found the root cause of the @nomadxyz_ bridge hack. Nothing to be done at this time except getting funds back from whitehats that drained preventively. We'll work with ecosystem members to prevent such issues in the future. h…
-
@cointelegraph
@cointelegraph
on x
The Nomad token bridge appears to be the latest token bridge to suffer a security exploit, losing nearly all of its crypto funds worth $190.7 million in total value locked. https://cointelegraph.com/...
-
@silvermanjacob
Jacob Silverman
on x
Why does this keep happening, asks only industry in which this keeps happening https://twitter.com/...
-
@nickadobos
Nick Dobos
on x
Lmao someone hacked a crypto bridge and other people copy pasted the hack The first decentralized looting Like someone broke into a bank and got away with most of the funds but let others run in and get the scraps they dropped https://twitter.com/...
-
@0xfoobar
@0xfoobar
on x
Congratulations to everyone who passed Nomad, the first stage of the Paradigm CTF challenge! Please assemble around the Uniswap V3 contract tomorrow at 5pm UTC for your next task
-
@el33th4xor
@el33th4xor
on x
The Nomad bridge, used by non-Avalanche chains, was hacked today. Nomad was the official bridge for EVMOS (Cosmos EVM), Moonbeam (Polkadot EVM), and Milkomeda (another EVM). This thread provides a post-mortem. The Avalanche Bridge is unaffected. https://twitter.com/...
-
@fatmanterra
Fat Man
on x
A message from 🍉🍉🍉.eth, a Milady holder who received hundreds of thousands of dollars from the Nomad bridge via the exploit: “im returning this money, fbi pls calm down. no i didnt plan to steal it and yes i know this address is doxed” Hope the others do the same! https://twitter…
-
@levicook
@levicook
on x
Bridge failures suck.
-
@bradwilson
@bradwilson
on x
At this point you'd have to be out of your mind to put any money into crypto. https://twitter.com/...
-
@matthuang
Matt Huang
on x
Another month, another bridge hack. https://twitter.com/...