Nomic Bug Exposes Critical Vulnerability in nBTC Backing
A critical security flaw in Nomic's custom IBC forwarding path allowed an attacker to mint unbacked nBTC on June 25, which remained hidden for a staggering 74 days.
The bug, discovered by Osmosis, enabled the attacker to double-spend nBTC and send false vouchers to Osmosis. The team promptly froze deposits and withdrawals involving Nomic and Alloyed BTC to prevent further exploitation.
A total of 39.84 nBTC, representing approximately 36% of Alloyed BTC's backing, was affected by the exploit. To rectify the situation, Osmosis turned to governance for a fix, proposing the seizure of assets from the attacker's wallet and using community pool funds to cover the remaining balance.
An independent researcher known as Rarma identified the issue, attributing it to Nomic's system accidentally creating duplicate bitcoin deposits. This oversight allowed the attacker to mint extra nBTC without verification.