Nomic Bridge Bug Leaves a Third of Wrapped Asset Unbacked
A bug in the Nomic bridge allowed an attacker to double-spend nBTC, a token meant to be backed one-to-one by real BTC. The exploit occurred on or around September 7 and 8, when an attacker found a flaw in the custom forwarding mechanism of Nomic's bridge.
The attacker was able to mint vouchers for bitcoin that were never actually deposited, which flowed into Osmosis's Alloyed BTC contract. This pooled asset blends bitcoin representations from multiple bridges into one liquid token.
Osmosis responded by freezing 22.65 BTC linked to the attacker's address through an emergency validator upgrade and pausing minting, redemptions, and new Nomic deposits. Trading of bitcoin-linked assets in existing liquidity pools stayed live, but with a warning attached about elevated risk.