Nomic Bridge Code Vulnerability Drains Nearly $3 Million from Osmosis
A vulnerability in Nomic's bridge code allowed an attacker to drain nearly $3 million from Osmosis' Bitcoin reserve. The exploit, which occurred over a period of 74 days, involved minting fake bitcoin that didn't exist and moving it onto the Osmosis platform.
The bug was discovered by independent researcher Rarma, who found that Nomic's code allowed for double-spending nBTC - Nomic's bitcoin-pegged token. This enabled the attacker to send false vouchers to Osmosis, which were then treated as backed by real BTC.
Osmosis froze 22.65 BTC worth around $1.8 million still sitting at the attacker's address through an emergency validator upgrade, leaving a shortfall of around $1.35 million. The exchange has paused minting and redemptions while it sorts out the issue.