Nomad Hack

TOTAL LOST $190M
Critical #52 All-Time Trusted Root Exploit / Other ethereum

Summarize with AI

Affected Chain ethereum Incident surface
Recovered $36.3M 19.1% returned
All-Time Rank #52 By amount stolen
Auditors 1 Prior security audit

Incident Overview

The Nomad bridge was exploited for aprox. $190 million by what has to be declared as Web3`s first "crowd-looting" event.

The Nomad bridge is an interoperability protocol that connects five different blockchains, namely Avalanche, Ethereum, Evmos, Milkomeda C1 and Moonbeam. The initial attack appears to have taken place with this transaction, where 100 (WBTC) were extracted from the protocol; https://etherscan.io/tx/0x61497a1a…0a8f17. This hack was made possible by an operational error incurred by the team, which had been found and commented upon in an audit report made by Quantstamp. Essentially, at the initialization of the contract the "process()" function checks messages for an acceptable merkle root. The team accidentally marked the zero root (0x00) as acceptable. This error enabled every message to be auto-proven by default. Essentially, the attacker was able to process transactions without any proving by calling the function "process()".

This information spread within the community and all that was needed to participate in the looting of the protocol was finding a transaction that worked and copy-pasting the transaction with the wallet of desire at the receiving end. This is the reason why tokens were predominantly extracted in the exact same denomination.

The initial attack was followed by hundreds of EOA`s extracting assets such as $WBTC, $FXS, $C3, $DAI, $USDC from the bridge. Amongst the looters were reputable hackers from other exploits such as the Rari Capital Exploiter as well as White hat hackers who intend to return the funds.

As the time of this writing approx. $32 million have been returned to the Nomad Recovery Funds Address https://etherscan.io/address/0x94A84433…1bF154 by white hat hackers and cooperating culprits.

Attacker address: https://etherscan.io/address/0x56d8b635…aac4e3

Attacker contract address: https://etherscan.io/address/0xf57113d8…f42777

Attack transactions:

1) https://etherscan.io/tx/0x61497a1a…0a8f17

2) https://etherscan.io/tx/0x29b67e07…f3fd57

3) https://etherscan.io/tx/0xdf6bef0d…af1b45

4) https://etherscan.io/tx/0x3dbed4a1…3dcdd9

Nomad Recovery Funds Address:

https://etherscan.io/address/0x94A84433…1bF154

Incident Report

Protocol / Project Nomad
Date of Incident
Affected Chain(s) ethereum
Attack Technique Trusted Root Exploit / Other
Classification Protocol Logic / Bridge
Primary Source View Post-Mortem

Protocol Information

Protocol Type Bridge
Affected Token Nomad: ERC20 Bridge
Smart Contract Language Solidity
Official Website www.nomad.xyz/
Protocol Twitter/X @nomadxyz_
Team Anonymous
Source Code Verified On-Chain

Market Context at Time of Hack

Token Categories
AI & Big Data Base Ecosystem AI Agents Virtuals Protocol Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of trusted root exploit / other and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with ethereum smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Nomad's contract logic - root cause: protocol logic / bridge
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Likely — with a thorough Trusted Root Exploit / Other audit checklist and test coverage
Audited by Quantstamp — still lost $190M. Prior audits don't guarantee safety, especially after post-audit code changes.

If you're auditing a protocol with similar architecture to Nomad, these are the critical security checks that could have prevented this incident (August 2022).

  • Verify all logic paths related to Trusted Root Exploit / Other are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Funds Recovery

19.1%

Recovered

$36.3M

Net Loss

153710000

Security Audit History

Sources & References

Learn to Prevent the Next Nomad

The Nomad hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial