Desk live·
ForensicPost
Breaches/Finance/File 22-0801

Nomad Bridge Lost $190 Million as Hundreds of Addresses Copied One Transaction

A routine upgrade to the Nomad bridge set a trusted root to zero — the same value that meant "unverified" — so every message validated. The exploit required no skill to reuse, and hundreds of addresses joined in.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetNomad bridge
ActorUnattributed
S. Rosler11 min readConfidence: high3 sources reviewed

On 1 August 2022 around $190 million was drained from the Nomad token bridge. The cause reported was a routine upgrade in which a trusted root value was initialised to zero — a value that also signified an unproven message, with the result that messages carrying invalid proofs were accepted as valid.

Reuse required no understanding of the flaw: taking a successful transaction and substituting one’s own address was sufficient. Analysis reported 41 addresses accounting for around $152 million, among them automated trading bots and an address associated with a separate exploit.

We Have No Other Crowd

Every other incident in this database has an actor or a set of them — an operation, an affiliate, a persona, an unnamed intruder. This one had a crowd, most of whom could not have found the flaw and did not need to.

That breaks the categories the desk uses. The record field for actor says "Unattributed" because there is no single party to attribute to, and the usual questions — dwell time, lateral movement, exfiltration — do not apply to a person who copied a transaction they saw in a block explorer.

A Default Value Meant Two Things

Initialising a variable to zero is ordinary practice. The defect was that zero already carried meaning in this system, and the meaning was "not yet proven".

So a routine initialisation asserted that every unproven message was trusted. We have recorded comparable category confusions at 22-0930, where a mitigation described one exploit rather than the defect, and at 22-0922. None of these is a coding error in the way the word is usually meant; each is a system where two different things were represented identically.

Public Ledger, Public Theft

The attack was visible while it happened. Observers watched the balance fall in real time and could enumerate the addresses taking part.

Transparency did not slow it down; it accelerated it, because the working exploit was published by its own execution. We noted at 22-0417 that on-chain visibility makes this material unusually well evidenced. This is the same property producing the opposite outcome, and both are worth recording against the claim that transparency is straightforwardly a security benefit.

How we reported this

Compiled from contemporaneous reporting and published incident analyses, listed below. No address or individual is named. Reporting described some participants returning funds; this file does not attempt to quantify recoveries, which were still moving when the incident was reported. Later law-enforcement action relating to the incident is outside its scope. Graded high on the mechanism. Corrections: corrections@forensicpost.com.

Sources
  1. Explained: The Nomad Hack (August 2022)Halborn
  2. Nomad Bridge Exploit Incident AnalysisCertiK
  3. Crypto Bridge Nomad Loses $190M in "Free-For-All" AttackBankInfoSecurity
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary