Nomic nBTC Bridge Exploit Results in $3.15 Million Loss
A bug in Nomic's forwarding mechanism allowed an attacker to double-spend nBTC. The incident led to the freezing of funds and a governance proposal to recover losses.
An attacker exploited a bug in Nomic’s custom forwarding mechanism, which enabled them to double-spend nBTC and issue unbacked vouchers to Osmosis. It was confirmed that Osmosis and the Inter-Blockchain Communication (IBC) protocol were not compromised during this incident. The attack resulted in a loss of approximately $3.15 million, with 39.84 nBTC of the minted supply sitting in Alloyed BTC, representing around 36% of its backing.
In response to the exploit, Osmosis took immediate action by freezing the flows of Nomic and Alloyed BTC. Validators were upgraded to prevent further issues, and 22.65 BTC was frozen in the attacker’s address. This proactive measure aimed to mitigate the impact of the exploit and protect the remaining assets.
Governance will be asked to seize the frozen funds from the attacker’s address and cover the remaining losses from the community pool. The incident highlights the vulnerabilities in custom mechanisms and the importance of swift action in the face of security breaches.
