Nomad Recovers Nearly $20M of Stolen $190M

Recovered funds in Nomad’s official wallet have increased over the past 24 hours

article-image

Blockworks exclusive art by axel Rangel

share

key takeaways

  • Nomad is considering a 10% bounty for hackers who return most of their stolen funds
  • The largest return to date has been 100 ETH ($160,000)

Token bridge Nomad suffered a hack on Monday that resulted in a loss of $190 million in cryptocurrencies. So far, $19.4 million of those funds have been sent back to the protocol.

Nomad created a recovery wallet address in a plea to the “white hat hackers and ethical researcher friends who have been safeguarding ETH/ERC-20 tokens” to return the lost digital assets.

The wallet was set up in association with custodian bank Anchorage Digital. Nomad has since taken to Twitter to thank some of its contributors.

Loading Tweet..

Nomad’s hack resulted from an issue in the code itself, 1KX Research told Blockworks. Nomad developers had accidentally enabled a code setting which automatically verified any transaction script sent to the protocol, as long as they had a default “root” of “0x00.”

The result was a free-for-all involving onlookers rushing to submit illicit transactions, quickly draining the token bridge of all user funds kept inside its associated smart contract.

Nomad has acknowledged that some users wanted “more consistent communications” and apologized for not having “provided that up to this point.”

The firm announced via Twitter that hackers who return at least 90% of the total funds they hacked may be considered for a bounty of up to 10%. 

This incident is the third-biggest cryptocurrency hack this year after the Solana-to-Ethereum Wormhole bridge and the Axie Infinity Ronin bridge exploits, which lost $325 million and $625 million, respectively, valued at the time of the exploits.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Avail.jpg

Research

Data publishing costs have historically been a bottleneck for rollups, and as more rollups launch, interoperability will continue to be a major challenge. Avail presents a potential solution to rollup fragmentation through its three products: Avail DA, Nexus, and Fusion, which together aim to unify the web3 experience.

article-image

Short-term “sell the news” reactions could follow new BTC price peaks months from now, industry watchers say — but only if history repeats itself

article-image

While crypto fundraising remains well off its bull market highs, Q1 data shows capital is returning to the space

article-image

Billed as a better BRC-20 fungible token standard, Bitcoin Runes launches tomorrow

article-image

Bitcoin miners need to explore unconventional energy avenues or be buried by the financial realities created by this halving

article-image

BlackRock’s iShares Bitcoin Trust continues to see daily positive net flows, though its inflow total for a single day hit a new low Wednesday

article-image

Binance is making moves, from receiving a new license in Dubai to switching its SAFU fund to USDC