Skip to content
Yieldo

Nomad 🌉 Bridge

$190.0M
Funds stolen
Funds returned
01 Aug 2022
Date of incident
Technique
Forged Proof
Classification
Bridge & Cross-Chain
Target type
DeFi Protocol
Affected chains
Ethereum
Source
No public source link

On August 1, 2022, the Nomad token bridge was drained of roughly $190 million in a little over two hours, after an authentication bug let anyone withdraw funds without a valid proof. Nomad's own post-mortem traces the flaw to a routine contract upgrade three weeks earlier. Unlike most bridge hacks, no private key was stolen and no signature was forged — a misconfigured contract simply accepted empty proofs as valid, and once the first withdrawal appeared on Etherscan, hundreds of unrelated wallets copied it to drain the rest.

How the exploit worked

Nomad verifies cross-chain messages with a Merkle root: a payout only clears on the destination chain if its proof matches a root that has been formally confirmed. During a June 21, 2022 upgrade, the Replica contract was initialized with the "empty" root — 0x00 — marked as already confirmed, a placeholder meant to represent "nothing proven yet." A bug in the acceptableRoot() check meant any message with no real proof also defaulted to that same 0x00 root — and since the contract treated 0x00 as confirmed, unproven messages were accepted like proven ones (Halborn).

In practice, a withdrawal call didn't need a genuine cryptographic proof at all — it just had to omit one. The first person to notice, later charged as Alexander Gurevich, drained a modest $2.89 million this way. But the winning transaction was public on a block explorer, so anyone could copy its calldata, swap in their own address, and resubmit it — no Solidity required. Rekt called it a "free-for-all": within roughly 2.5 hours, several hundred addresses joined in, with the top three alone extracting $95 million. That is the sense in which "trusted root" describes the bug — the contract's root of trust had silently become a value nobody needed to prove.

Aftermath

Nomad disabled the bridge UI and unenrolled the vulnerable contracts roughly three hours in. It then offered exploiters a 10% white-hat bounty: return at least 90% to a published address and face no legal action. Recovery was slow and partial — about $20 million came back within two days, reaching $36 million by late August, around 19% of the total. Working with Chainalysis and TRM Labs, Nomad traced funds across 300-plus addresses. The bridge relaunched in limited form in December 2022, but its TVL never recovered — it sits around $1–2 million today.

Two enforcement actions followed years later. In August 2023, US prosecutors in the Northern District of California indicted Gurevich on eight counts including money laundering and computer crimes; he was arrested at Ben Gurion Airport allegedly trying to flee to Russia under a changed name and is fighting extradition (CoinCentral). Separately, in December 2025 the FTC proposed a settlement with Nomad's operator, Illusory Systems, alleging it marketed itself as "safety-focused" while lacking basic security testing and incident-response procedures; the settlement requires returning recovered funds to users and regular independent audits going forward (Cryptopolitan).

What this means

  • Bridges pool liquidity from many users behind one verification contract — a single misconfigured check drains everyone at once, not just the party who found it.
  • No cryptography was broken and no key was stolen; a pure access-control mistake in an upgrade was enough, so upgrade review matters as much as key management.
  • Once an exploit is public on-chain, anyone able to edit calldata can copy it — visibility of the first transaction is itself a risk multiplier.
  • Voluntary bounty programs recovered under a fifth of the funds; smart-contract exploits, unlike custodial breaches, offer no way to freeze or claw back assets once they leave the contract.

On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.