Nomic and Osmosis allBTC: the 40.65 BTC nobody noticed for 74 days

PublicAML · On-chain investigation · 23 September 2026

On 25 June 2026 an attacker combined two bugs in the Nomic bridge to mint 40.65 nBTC on Osmosis with no bitcoin behind it. Nobody noticed until September. By then about 18 BTC worth had left through Axelar and Circle into Ethereum and, within three days of the exploit, into Tornado Cash: exactly 671.1 ETH. The other 22.65 is still sitting where the attacker parked it, which is why Osmosis could freeze it. One detail ties the Osmosis and Ethereum addresses together beyond doubt: two days before the exploit, the Ethereum address paid the Osmosis one its gas.

40.65 nBTC

minted with no BTC behind it, 25 Jun 2026

74 days

before anyone noticed — the chain halted on 7 Sep

671.1 ETH

into Tornado Cash in 33 deposits, 25 and 28 Jun

22.65 allBTC

still on the attacker’s Osmosis address, frozen

What happened

Nomic is the chain behind nBTC, a bitcoin token used on Osmosis as one of the reserves behind Alloyed BTC (allBTC). On 25 June an attacker combined two bugs in Nomic’s forwarding mechanism into one transaction that delivered 40.65 nBTC to Osmosis with no bitcoin locked behind it. The fake nBTC was as good as real nBTC to every pool that took it. Osmosis only found the hole when Nomic stopped producing checkpoints in early September, and froze allBTC on 9 September. About 36% of allBTC turned out to have nothing behind it.

The same actor on both chains

The address that received the nBTC on Osmosis is osmo1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vtzltn. The Ethereum address the proceeds went to is 0x8f36FD9FfC0a8cA373AA7A4787292536a489d2B5. Public write-ups put the two side by side; the chain says more. On 23 June, two days before the exploit, the Ethereum address sent two small WETH payments through Squid, Axelar’s router, and both landed on the Osmosis address: gas, so a fresh account could transact. Forty minutes later the Osmosis address sent a test transfer to nomic1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8cgz4wt — the same key on Nomic. The attacker set up both ends first, then waited two days.

When (UTC, 2026)FromToAmountTx
23 Jun 02:020x8f36FD…89d2B5osmo1wq7…vtzltn2 × 0.01 WETH
gas for the Osmosis address, via Squid
0xf18adb…0f183f
23 Jun 03:01osmo1wq7…vtzltnnomic1wq…cgz4wttest transfer
same key on Nomic
9CDD3729…FC2D44
25 Jun 21:50nomic1wq…cgz4wtosmo1wq7…vtzltn40.65 nBTC
unbacked nBTC delivered
25 Jun 22:11osmo1wq7…vtzltn0x8f36FD…89d2B58 WBTC → 303.01 ETH
Axelar, converted by Squid
468D435D…37EE82
25 Jun 22:14osmo1wq7…vtzltn0x8f36FD…89d2B51.5 WBTC → 57.10 ETH
Axelar, converted by Squid
EF6FFD30…A30794
25 Jun 22:29osmo1wq7…vtzltn0x8f36FD…89d2B58.10 ETH
Axelar, converted by Squid
F879A157…A1D1D7
25 Jun 23:24osmo1wq7…vtzltn0x8f36FD…89d2B5112,509 USDC → 71.15 ETH
via Circle, swapped on Ethereum
65BD688B…98BE8E
25 Jun 22:56–23:460x8f36FD…89d2B50xd90e2f…24F31b439.1 ETH
Tornado Cash, 26 deposits
0x2df204…9bfbb0
28 Jun 18:33osmo1wq7…vtzltn0x8f36FD…89d2B56.16 WBTC → 232.40 ETH
Axelar, converted by Squid
70DFD62F…182904
28 Jun 18:41–18:460x8f36FD…89d2B50xd90e2f…24F31b232.0 ETH
Tornado Cash, 7 deposits
0x1aab9a…b730c2
17 Jul 22:44osmo1wq7…vtzltnosmo1wq7…vtzltn22.65 nBTC → 22.65 allBTC
swapped into allBTC; frozen
8305D3D4…1E8D7E

From fake nBTC to Tornado Cash in three hours

At 21:50 UTC on 25 June the unbacked nBTC arrived on Osmosis. Within 25 minutes the attacker sold 18 of it for Axelar-wrapped bitcoin in pool 1868 — the allBTC pool itself — and started bridging: 8 WBTC, then 1.5 WBTC, then 8.1 ETH through Axelar, each converted to ETH by Squid on arrival at the Ethereum address. A last piece went out as 112,509 USDC over Circle’s bridge and was swapped for 71.15 ETH.

The Tornado deposits began at 22:56, before the last bridge had even landed: 439.1 ETH in 26 deposits by 23:46. On 28 June the attacker bridged another 6.16 WBTC, received 232.4 ETH, and put 232 ETH into Tornado within eight minutes. In all, 671.1 ETH — the figure the reports carry, now with every deposit behind it. 0.575 ETH is still on the Ethereum address.

Why 22.65 could be frozen

On 17 July the attacker swapped the remaining 22.65 nBTC into allBTC and left it on the Osmosis address. That is the whole of the frozen amount: 40.65 minted, about 18 laundered, 22.65 never left the address. Seizing it through a chain upgrade returns claims on the pool, not bitcoin — the nBTC behind them was fake — so the shortfall that actually has to be covered is the 18 that left.

The attacker’s Ethereum gas, 0.037 ETH on 22 June, came from 0x37EaF2AD33160Aaae7bdd1C6902c4a2862e1270D. That is not the attacker’s own wallet by any sign we can read: it takes one-off payments from hundreds of unrelated addresses and pays out in all directions, the pattern of a small exchange service. We have not labelled it and do not treat it as part of the attack.

The Ethereum address is labelled in PublicAML. The Osmosis address is listed here but cannot be scored yet: PublicAML does not cover Osmosis.

Sources: Osmosis chain data (public REST nodes), Axelar GMP records (Axelarscan) and Ethereum data (Blockscout), read on 23 September 2026; the exploit mechanism and the 40.65 figure as stated by Osmosis and Nomic; the Ethereum address as first published in press coverage of the incident. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.