|

Nomad bridge drained of nearly $200m in exploit

The exploit calls the security of cross-chain token bridges into question once again.

The cross-chain token bridge Nomad was exploited Monday, with attackers draining the protocol of virtually all of its funds. The total value of cryptocurrency lost to the attack totaled near $200 million.

Nomad, like other cross-chain bridges, allows users to send and receive tokens between different blockchains. Monday’s attack is the latest in a string of highly-publicized incidents which have drawn the security of cross-chain bridges into question.

CoinDesk has reached out to Nomad for comment but hadn’t heard back at the time of writing. In a tweet, the team said it was investigating the incident.

What Happened?

Bridges typically work by locking up tokens in a smart contract on one chain and then reissuing those tokens in “wrapped” form on another chain.

If the smart contract where tokens are initially deposited gets sabotaged – as happened in Nomad’s case – the wrapped tokens no longer have any backing, which can render them worthless.

Sam Sun, a researcher at crypto investment firm Paradigm, explained on Twitter that a recent update to one of Nomad’s smart contracts made it easy for users to spoof transactions, meaning people could withdraw money from the bridge that didn’t actually belong to them.

Unlike some bridge attacks, where a single culprit is behind the entire exploit, the Nomad attack was a free for all.

“... you didn't need to know about Solidity or Merkle Trees or anything like that. All you had to do was find a transaction that worked, find/replace the other person's address with yours, and then re-broadcast it,” Sun explained.

Nomad: A 'Secure' Alternative?

Bridge attacks have become more frequent in recent months as crypto-users have demonstrated an increased appetite for swapping assets between different blockchains.

While cross-chain bridges have made it possible for upstart blockchains to proliferate, bridge failures can be devastating for smaller chains that rely on them for a large amount of their total liquidity.

Evmos, one of the newer blockchains serviced by Nomad, tweeted that it would be “brainstorming community solutions” to the Nomad attack given that it “significantly impacts initial Evmos [total value locked].”

The largest decentralized finance (DeFi) attack in history, April’s Ronin bridge attack, saw over $600 million worth of crypto siphoned out of the bridge that powers the blockchain-based game Axie Infinity.

Just a few months before that, over $300 million was drained from the Wormhole bridge, wreaking havoc across the Solana blockchain community and the wider decentralized finance (DeFi) ecosystem.

Nomad sold investors on the vision that it would be fundamentally more secure than alternative platforms.

Just last week, it revealed that crypto heavyweights Coinbase Ventures and OpenSea were among those who participated in an April seed round which valued the company at $225 million.

Author

CoinDesk Analysis Team

CoinDesk is the media platform for the next generation of investors exploring how cryptocurrencies and digital assets are contributing to the evolution of the global financial system.

More from CoinDesk Analysis Team
Share:

Editor's Picks

Crypto Today: Bitcoin, Ethereum, XRP recovery slows amid incessant capital outflows

The cryptocurrency remains in a broader corrective bias on Friday, despite majors such as Bitcoin (BTC), Ethereum (ETH), and Ripple (XRP) holding slightly higher than early-week support levels.

Cardano: Whale selling, cautious derivatives limit ADA rebound

Cardano is trading near $0.170 at the time of writing on Friday after staging a modest rebound from last week's sharp correction. However, the recovery remains fragile as large holders have resumed reducing their positions, adding fresh selling pressure to ADA.

Experts agree: Bitcoin nears bottom, but weak demand raises doubts

Bitcoin (BTC) is trading above $63,000 at the time of writing on Friday after rebounding from the key 200-week Simple Moving Average (SMA) near $62,000, a level widely viewed as key long-term support.

Pi Network Price Forecast: Bulls attempt comeback as bearish strength fades

Pi Network is trading at around $0.120 on Friday after a modest recovery the previous day. Despite this recent rebound, traders should be cautious as a scheduled unlock of 14.8 million PI tokens on Friday could limit the token's recovery potential by increasing market supply.

Experts agree: Bitcoin nears bottom, but weak demand raises doubts
Bitcoin (BTC) is trading above $63,000 at the time of writing on Friday after rebounding from the key 200-week Simple Moving Average (SMA) near $62,000, a level widely viewed as key long-term support. The recovery may suggest that Bitcoin has found a floor after a sharp correction that spanned more than a month, but some warning signs persist.
Nomad bridge drained of nearly $200m in exploit