The exploit calls the security of cross-chain token bridges into question once again.

The cross-chain token bridge Nomad was exploited Monday, with attackers draining the protocol of virtually all of its funds. The total value of cryptocurrency lost to the attack totaled near $200 million.

Nomad, like other cross-chain bridges, allows users to send and receive tokens between different blockchains. Monday’s attack is the latest in a string of highly-publicized incidents which have drawn the security of cross-chain bridges into question.

CoinDesk has reached out to Nomad for comment but hadn’t heard back at the time of writing. In a tweet, the team said it was investigating the incident.

What Happened?

Bridges typically work by locking up tokens in a smart contract on one chain and then reissuing those tokens in “wrapped” form on another chain.

If the smart contract where tokens are initially deposited gets sabotaged – as happened in Nomad’s case – the wrapped tokens no longer have any backing, which can render them worthless.

Sam Sun, a researcher at crypto investment firm Paradigm, explained on Twitter that a recent update to one of Nomad’s smart contracts made it easy for users to spoof transactions, meaning people could withdraw money from the bridge that didn’t actually belong to them.

Unlike some bridge attacks, where a single culprit is behind the entire exploit, the Nomad attack was a free for all.

“... you didn't need to know about Solidity or Merkle Trees or anything like that. All you had to do was find a transaction that worked, find/replace the other person's address with yours, and then re-broadcast it,” Sun explained.

Nomad: A 'Secure' Alternative?

Bridge attacks have become more frequent in recent months as crypto-users have demonstrated an increased appetite for swapping assets between different blockchains.

While cross-chain bridges have made it possible for upstart blockchains to proliferate, bridge failures can be devastating for smaller chains that rely on them for a large amount of their total liquidity.

Evmos, one of the newer blockchains serviced by Nomad, tweeted that it would be “brainstorming community solutions” to the Nomad attack given that it “significantly impacts initial Evmos [total value locked].”

The largest decentralized finance (DeFi) attack in history, April’s Ronin bridge attack, saw over $600 million worth of crypto siphoned out of the bridge that powers the blockchain-based game Axie Infinity.

Just a few months before that, over $300 million was drained from the Wormhole bridge, wreaking havoc across the Solana blockchain community and the wider decentralized finance (DeFi) ecosystem.

Nomad sold investors on the vision that it would be fundamentally more secure than alternative platforms.

Just last week, it revealed that crypto heavyweights Coinbase Ventures and OpenSea were among those who participated in an April seed round which valued the company at $225 million.


All writers’ opinions are their own and do not constitute financial advice in any way whatsoever. Nothing published by CoinDesk constitutes an investment recommendation, nor should any data or Content published by CoinDesk be relied upon for any investment activities. CoinDesk strongly recommends that you perform your own independent research and/or speak with a qualified investment professional before making any financial decisions.

Recommended content


Recommended Content

Editors’ Picks

Ethereum has lost its “ultra” sound money status, faces key rectangle resistance hurdle

Ethereum has lost its “ultra” sound money status, faces key rectangle resistance hurdle

Ethereum is up 0.5% on Thursday following a recent analysis showing that the top altcoin lost its "ultra" sound money narrative. Meanwhile, ETH ETFs recorded net inflows for the first time after nine days of consecutive outflows.

More Ethereum News
Solana bears dominate market as SunPump has potentially led to less demand for SOL

Solana bears dominate market as SunPump has potentially led to less demand for SOL

Solana is down 2.5% on Thursday following bearish signals across its funding rate and total fees captured. SOL's weak performance could also be linked to the declining traction seen in its meme coin generation platform Pump.fun.

More Solana News
AI tokens see narrow gains as Wall Street banks raise price targets on NVDA

AI tokens see narrow gains as Wall Street banks raise price targets on NVDA

AI tokens NEAR, ICP, RENDER and TAO briefly traded in the green on Thursday following Wall Street banks' positivity toward Nvidia's earnings report. While a correction followed, these tokens could rally if NVDA meets expectations.

More Cryptocurrencies News
XRP back above $0.57 even as Ripple traders take $8 million in profits

XRP back above $0.57 even as Ripple traders take $8 million in profits

Ripple (XRP) traders have consistently taken profits on their holdings in the last two weeks, per Santiment data. Once again, traders have grabbed $8.36 million in profit so far on Thursday. Typically, profit-taking negatively influences the asset as it increases the selling pressure. 

More Ripple News
Bitcoin: Will BTC continue its ongoing decline?

Bitcoin: Will BTC continue its ongoing decline?

Bitcoin (BTC) trades above $59,000 on Friday, but it has lost 7.5% this week so far after being rejected around the daily resistance of $65,000. The decline is supported by lower demand from the US spot Bitcoin ETFs, which registered a net outflow of $103.8 million, falling Bitcoin's Coinbase Premium Index, and a spike in Network Realized Profit/Loss. However, some investors seem to be taking the chance to buy BTC amid this price dip, as shown by the Exchange Netflow data.

Read full analysis
Moneta Markets review 2024: All you need to know

Moneta Markets review 2024: All you need to know

VERIFIED In this review, the FXStreet team provides an independent and thorough analysis based on direct testing and real experiences with Moneta Markets – an excellent broker for novice to intermediate forex traders who want to broaden their knowledge base.

Read More

BTC

ETH

XRP