Nomad Hack
Incident Overview
The Nomad bridge was exploited for aprox. $190 million by what has to be declared as Web3`s first "crowd-looting" event.
The Nomad bridge is an interoperability protocol that connects five different blockchains, namely Avalanche, Ethereum, Evmos, Milkomeda C1 and Moonbeam. The initial attack appears to have taken place with this transaction, where 100 (WBTC) were extracted from the protocol; https://etherscan.io/tx/0x61497a1a…0a8f17. This hack was made possible by an operational error incurred by the team, which had been found and commented upon in an audit report made by Quantstamp. Essentially, at the initialization of the contract the "process()" function checks messages for an acceptable merkle root. The team accidentally marked the zero root (0x00) as acceptable. This error enabled every message to be auto-proven by default. Essentially, the attacker was able to process transactions without any proving by calling the function "process()".
This information spread within the community and all that was needed to participate in the looting of the protocol was finding a transaction that worked and copy-pasting the transaction with the wallet of desire at the receiving end. This is the reason why tokens were predominantly extracted in the exact same denomination.
The initial attack was followed by hundreds of EOA`s extracting assets such as $WBTC, $FXS, $C3, $DAI, $USDC from the bridge. Amongst the looters were reputable hackers from other exploits such as the Rari Capital Exploiter as well as White hat hackers who intend to return the funds.
As the time of this writing approx. $32 million have been returned to the Nomad Recovery Funds Address https://etherscan.io/address/0x94A84433…1bF154 by white hat hackers and cooperating culprits.
Attacker address: https://etherscan.io/address/0x56d8b635…aac4e3
Attacker contract address: https://etherscan.io/address/0xf57113d8…f42777
Attack transactions:
1) https://etherscan.io/tx/0x61497a1a…0a8f17
2) https://etherscan.io/tx/0x29b67e07…f3fd57
3) https://etherscan.io/tx/0xdf6bef0d…af1b45
4) https://etherscan.io/tx/0x3dbed4a1…3dcdd9
Nomad Recovery Funds Address:
https://etherscan.io/address/0x94A84433…1bF154
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Nomad, these are the critical security checks that could have prevented this incident (August 2022).
- Verify all logic paths related to Trusted Root Exploit / Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$36.3M
Net Loss
153710000
Security Audit History
- Quantstamp Report
Sources & References
- 01
- 02
- 03
- 04
Learn to Prevent the Next Nomad
The Nomad hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.