Decentralized Ecosystem Shaken by Alby and Nomic Security Incidents
Two major security incidents shook the decentralized ecosystem on Wednesday, as Alby and Nomic faced breaches that put funds at risk. Alby confirmed a vulnerability in its self-hosted Hub software, affecting versions v1.7.0 through v1.18.5. The flaw allows an attacker to transfer assets out of the wallet without authorization if the user's administrative API remains exposed to the internet.
Alby urged node operators to upgrade to version 1.24.0 and restrict public traffic using firewalls, while security researchers from Team Red and Project Loupe formally disclosed the vulnerabilities for remediation.
In a separate incident, Osmosis reported an exploit targeting the Nomic network, which issues the wrapped asset nBTC. The attacker identified a flaw in Nomic's forwarding mechanism, enabling them to forge proofs and execute a double-spend of the asset onto Osmosis.
Financial exposure was significant, with 39.84 nBTC of the total minted supply backing the Alloyed BTC asset, accounting for roughly 36% of its total reserves at the time of the breach. The Osmosis moderation subDAO temporarily suspended deposits and withdrawals linked to Nomic and the Alloyed BTC liquidity pool.