It's not a great day for the Nomad cryptocurrency project,eroticism and indian miniatures nor for its high-profile investors.
Nomad is a cross-chain bridge, meaning it allows users to transfer cryptocurrency tokens from one blockchain to another. So, if you want to move some ETH, USDC or WBTC from the Ethereum blockchain to the Moonbeam blockchain, Nomad makes it as easy as a couple of clicks.
Behind the scenes, the bridge "locks" your money on one side and spews out the same amount in so called "wrapped" tokens on the other side. Over time, if a bridge is popular, it can have a lot of funds (think hundreds of millions) locked in its smart contracts, and if someone finds a security hole in those smart contracts, some or all of those funds can be stolen. An additional problem with crypto bridges, as once pointed out by Ethereum co-founder Vitalik Buterin, is that they're by design vulnerable to attacks on two sides.
In case of Nomad, as pointed out by several experts on Twitter, it appears that a bug in its smart contract allowed anyone to construct a cryptocurrency transaction in such a way to send one amount of crypto on one side, but receive a larger amount on the other side. Yes, you could literally send 0.1 BTC on one side and get 100 BTC on the other side.
This is where things get interesting. Typically, when a security hole like this gets unearthed, a competent hacker or a small group will drain all of the funds within minutes. But this time, after someone successfully stole some money from the Nomad bridge, others joined in and took some money for themselves.
One reason why this was possible was that the security hole was so blatant that it didn't require a lot of expertise to replicate. As security researchers @samczsun pointed out, "all you had to do was find a transaction that worked, find/replace the other person's address with yours, and then re-broadcast it," and that's exactly what people did. Think of it as the crypto equivalent of mass looting, with one person breaking a store window and hundreds joining in to steal what they can.
The word is not final on the total amount that was stolen, but it appears that all of Nomad's funds were drained, and estimates go up to $190 million. A bit of silver lining is that, in case of open-to-all, high-profile hacks like this, white hat hackers will often drain some of the funds in order to keep them safe and return them later, but it's hard to assess how much of that was happening in this particular case.
This Tweet is currently unavailable. It might be loading or has been removed.
Nomad, which ironically calls itself "security-first cross-chain protocol," and claims that its mechanism requires "one honest actor to keep the entire system safe," said on Twitter that it's looking into the hack. The company told CoinDesk it has notified law enforcement, and that its goal is to "identify the accounts involved and to trace and recover the funds." Users should not used the Nomad bridge at least until the issue is resolved.
This Tweet is currently unavailable. It might be loading or has been removed.
Moonbeam Network went into "maintenance mode" following the hack, meaning that regular users were not able to execute transactions on the network. The team brought back the network after concluding that the security incident was not connected to the Moonbeam codebase.
The Nomad hack isn't the only or even the largest cryptocurrency hack in history; in March 2022, more than half a billion dollars was stolen from Ronin, and in June 2022, $100 million were stolen from Harmony.
Nomad is notable for being a very popular bridge on the Moonbeam and Evmos networks, and for receiving a $22.4 million seed round just days ago, with investors being high-profile companies including Coinbase, OpenSea, and Crypto.com.
Topics Cryptocurrency
Uber holds first Elevate Summit to further its plan for flying taxisSamsung and LG are working hard on phones that are basically all screenStriking portrait series celebrates the resilience of black Muslim Americans8 badass facts about Tom Hardy you might not knowGorilla Man is still crawling the London Marathon three days laterMLB player leaps over catcher to score acrobatic 'Major League II' style runJeff Goldblum's handing out free sausages in a 'Chef Goldblum's' truckApple launches global inTake a virtual tour of NYC's historic LGBTQ sites with this interactive mapGoogle Maps can now tell you where you parked your carGotham City and Metropolis are coming to this massive theme parkNordstrom is selling fake mud jeans for the unbelievably low price of $425Dude trolls Starbucks baristas with a bunch of weird containers to fill up with coffeeHigh school senior makes a powerful statement with her prom dressAmazon Echo Look is first smart home device Kim Kardashian could loveUber holds first Elevate Summit to further its plan for flying taxisIf you have a spare $1.4 million lying around, you can get this solid gold Darth Vader maskIndia's biggest movie ever is coming to a theater near youI've got a gut feeling: Harnessing the power of intuitionThis mobile game lets you 'clean up' plastic pollution from the ocean A Haribo factory is coming to the U.S. because gummy bear dreams do come true Jay Z will bring Trayvon Martin's story to the big and small screen 'Rogue' national park Twitter account wasn't so rogue after all, emails show Turns out, that viral website where kittens attack Trump may have trolled us all So it turns out Shaq doesn't actually believe the Earth is flat Disney boss drops hot new details on Han Solo, Luke Skywalker Interview: Maxine Waters thinks millennials can change politics for everyone (yes, everyone) Trump had fun in an 18 The 'Spider 'Sunless Sea' is a wild 350,000 Scorching heat from this 'artificial sun' could help fight climate change Concept design puts stunning U Can the CIA hack your iPhone? What you need to know about the WikiLeaks dump. Future of farming: smart autonomous drones with eyes on the field Deloitte's CEO gave her 15 You can re Kate Winslet's kick In defense of ghosting: It's nothing personal Adele dedicates song to her 'soul mate' London in an emotional tribute Google Home goes on a defensive rant if you ask it about the CIA
2.1912s , 10194.7109375 kb
Copyright © 2025 Powered by 【eroticism and indian miniatures】,Miracle Information Network