Osmosis discovers 40‑BTC nBTC exploit on Nomic after 74 days
Exploit uncovered after two‑month lag
On June 25, an attacker created more than 40 BTC worth of Nomic’s nBTC without any backing BTC. The breach was not detected by Osmosis, a Cosmos‑based decentralized exchange, until 74 days later, when a halt of the Nomic protocol triggered an investigation.
Key facts
- The attacker double‑spent nBTC using two bugs and minted 40.650602 BTC of nBTC on Osmosis with no real BTC behind it.
- Osmosis froze the attacker’s allBTC holdings after the exploit was discovered.
- Approximately $1 million worth of the loot was moved out as 671 ETH sent to Tornado Cash on Ethereum.
- Osmosis plans to recover the shortfall by seizing 22.65 allBTC, canceling a pending USDC.noble liquidity move, and pulling more allBTC from a community pool.
- Nomic appears inactive; its X account last posted in 2024 and its GitHub saw its last commit two years ago.
What Osmosis said
In a September 9 tweet, Osmosis explained that the exploit allowed the attacker to double‑spend nBTC and send false vouchers to Osmosis. The bug was in a custom forwarding mechanism on Nomic, not in Osmosis or the Inter‑Blockchain Communication (IBC) protocol.
Broader Cosmos context
Both Osmosis and Nomic are part of the Cosmos ecosystem, which recently faced other security incidents linked to a widely used Cosmos EVM module. Developers at Cosmos Labs were criticized for how they disclosed a separate bug, and KiiChain called its loss “avoidable” because a fix was published before alerting affected teams.
Confirmed details
The minting of 40.650602 BTC of nBTC, the 74‑day detection lag, the freezing of the attacker’s allBTC, and the $1 million cash‑out via 671 ETH are all supported by the Osmosis tweet and governance forum post.
Remaining uncertainties
Exact amounts of allBTC still frozen and the total amount that can be recovered from the community pool have not been disclosed. Nomic’s current maintenance status is unclear beyond the lack of recent activity.
Why it matters
The exploit shows how a vulnerability in a bridge can create unbacked tokens on a decentralized exchange, affecting the trust and backing of assets like allBTC that rely on cross‑chain bridges.
Next steps
Osmosis will execute its recovery plan, which includes seizing frozen allBTC, canceling a pending liquidity deployment, and drawing additional funds from its community pool to cover the 40 BTC shortfall.