Nomad Cross-Chain Bridge Lost Nearly $200 Million in ‘Chaotic, Free For All’ Exploit

Nomad allows users to send and get cryptocurrencies between different blockchains.

Advertisement
By Radhika Parashar | Updated: 2 August 2022 11:29 IST
Highlights
  • Nomad team yet to disclose its response around this attack
  • Nomad team has acknowledged the attack
  • The exploit happened on August 1

Repeated attacks on on-chain bridges have put their security under question

Photo Credit: Website/ Nomad

Nomad, a cross-chain bridge lost $200 million (roughly Rs. 1,570 crore) in what security researchers are calling a ‘free for all' exploit. Unlike conventional attacks, where one culprit is responsible for the exploit, Nomad's case was different. Sam Sun, a Paradigm researcher has explained that a recent update to a Nomad smart contract made it convenient for users to spoof transactions and withdraw funds from the bridge, which originally did not belong to them. As per Sun, this is one of the most chaotic exploits to have happened in the Web3 sector so far.

Nomad allows users to send and receive cryptocurrencies between different blockchains. Cross chain bridges like Nomad, typically lock tokens in a smart contract on one chain and reissue these tokens in ‘wrapped' form on another chain.

In Nomad's case, a smart contract where tokens were initially deposited was sabotaged making way for exploiters to act.

Advertisement

“This is why the hack was so chaotic — you didn't need to know about Solidity or Merkle Trees or anything like that. All you had to do was find a transaction that worked, find/replace the other person's address with yours, and then re-broadcast it,” Sun wrote as part of his Twitter thread, decoding the dynamics of the exploit on Nomad.

Advertisement

While the cross-chain bridge has not issued media statements on the incident, it has posted a tweet acknowledging that it is aware of the case.

Nomad's detailed response on the incident remains awaited.

Advertisement

Bridges have become a popular element of the cryptosphere now that more people have begun swapping assets between different blockchains.

These blockchain bridges have caught the attention of hackers, who are constantly looking at ways to exploit them.

Advertisement

In March, a hack attack on Axie Infinity's Ronin bridge depleted a whopping $625 million (roughly Rs. 4,729 crore) from the Sky Mavis gaming company. The Ronin Network, designed by Axie Infinity developer Sky Mavis, acts as a bridge between the video game and the blockchain, allowing cryptocurrencies to be transferred in and out of the game.

Back in February, the Wormhole Portal, that allows people to switch from one cryptocurrency to another, also suffered a breach and lost $322 million (roughly Rs. 2,410 crore) worth of Ether.


Why is Oppo making strange choices with its flagship Reno series? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Cryptocurrency, Nomad, Hack, Wormhole, Ronin
Advertisement

Related Stories

Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. Realme Narzo 90 Series 5G India Launch Announced
  3. Be Dune Teen OTT Release: When, Where to Watch the Marathi Comedy Drama
  4. Motorola Edge 70 With 5.99mm Slim Profile Will Launch in India on This Date
  5. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  6. New Shortcut Lets Scientists Run Complex Quantum Models on a Laptop
  7. Xiaomi India COO Talks About Next Redmi Note, AI, and IoT Strategy
  8. Battlefield 6's Next Season 1 Update Arrives This Week: All You Need to Know
  9. OpenAI Says ChatGPT Isn't Showing Ads to Paid Users
  1. Motorola Edge 70 India Launch Date Announced; Confirmed to Feature Triple 50-Megapixel Camera Setup
  2. Battlefield 6's 'Winter Offensive' Update Launches This Week With New Content, Audio Improvements and More
  3. Chinese Brands Aiming to Win Users with AI Features That Apple Lacks: Report
  4. Samsung Ballie Robot Reportedly Delayed Again, Won't Launch This Year
  5. Vivo S50, Vivo S50 Pro Mini Launch Date Announced; Colour Options Revealed
  6. Starlink Subscription Price in India Revealed as Elon Musk-Led Firm Prepares for Imminent Launch
  7. Google Releases Gemini 3 Deep Think Model to Its Most Expensive Subscription Tier
  8. Meta’s Phoenix Mixed Reality Smart Glasses Reportedly Delayed; Could Finally Launch in 2027
  9. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  10. OpenAI Clarifies It Isn’t Testing Ads on ChatGPT Despite User Claims
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.