{"id":13425,"date":"2022-08-02T18:20:41","date_gmt":"2022-08-02T18:20:41","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/cross-chain-bridge-nomad-loses-190-million-making-it-2022s-third-largest-crypto-heist-bitcoin-news\/"},"modified":"2022-08-02T18:20:41","modified_gmt":"2022-08-02T18:20:41","slug":"cross-chain-bridge-nomad-loses-190-million-making-it-2022s-third-largest-crypto-heist-bitcoin-news","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/cross-chain-bridge-nomad-loses-190-million-making-it-2022s-third-largest-crypto-heist-bitcoin-news\/","title":{"rendered":"Cross-Chain Bridge Nomad Loses $190 Million Making It 2022&#8217;s Third-Largest Crypto Heist \u2013 Bitcoin News"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div id=\"\">\n<header class=\"article__header\">\n<\/header>\n<div class=\"featured_image_container\">\n<\/div>\n<p><strong>On Monday, the cross-chain token bridge Nomad was attacked and hackers managed to siphon $190 million from the protocol, draining a great majority of the funds. The Nomad cross-chain bridge attack was the third-biggest crypto heist of 2022, and the ninth largest of all time.<\/strong><\/p>\n<h2>Nomad Cross-Chain Bridge Exploited for $190 Million<\/h2>\n<p>Cross-chain bridges in the world of decentralized finance (defi) just can\u2019t catch a break no matter how long they have been running and even after the bridges have been audited. On August 1, 2022, the cross-chain bridge <a href=\"https:\/\/www.nomad.xyz\/\">Nomad<\/a> suffered an attack that saw the bridge lose $190 million in crypto funds. Security experts at the blockchain auditing firm <a href=\"https:\/\/www.certik.com\/\">Certik<\/a> published an <a href=\"https:\/\/www.certik.com\/resources\/blog\/28fMavD63CpZJOKOjb9DX3-nomad-bridge-exploit-incident-analysis\">incident report<\/a> describing what happened.<\/p>\n<p>\u201cThe vulnerability was in the initialization process where the \u201ccommittedRoot\u201d is set as ZERO,\u201d Certik wrote. \u201cTherefore, the attackers were able to bypass the message verification process and drain the tokens from the bridge contract,\u201d Certik added, noting:<\/p>\n<blockquote>\n<p>The exploit occurred when a routine upgrade allowed verification messages to be bypassed on Nomad. Attackers abused this to copy\/paste transactions and were able to drain the bridge of nearly all funds before it could be stopped.<\/p>\n<\/blockquote>\n<figure id=\"attachment_540097\" aria-describedby=\"caption-attachment-540097\" style=\"width: 1280px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" class=\"wp-image-540097 size-full\" src=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2022\/08\/by-months.jpg\" alt=\"\" width=\"1280\" height=\"600\" srcset=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2022\/08\/by-months-300x141.jpg 300w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2022\/08\/by-months-1024x480.jpg 1024w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2022\/08\/by-months-768x360.jpg 768w, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2022\/08\/by-months.jpg 1280w\" sizes=\"(max-width: 1280px) 100vw, 1280px\"\/><figcaption id=\"caption-attachment-540097\" class=\"wp-caption-text\">Number of crypto project attacks by month, according to researchers at Comparitech.<\/figcaption><\/figure>\n<p>Cross-chain bridges have been suffering from exploit after exploit since they were first introduced. At the end of March, the <a href=\"https:\/\/news.bitcoin.com\/axie-infinity-loses-620-million-after-hacker-compromised-ronin-validators\/\">largest hack of 2022<\/a> saw $620 million stolen from Axie Infinity\u2019s Ronin bridge. Researchers at Comparitech detail that the Nomad bridge attack was the third-largest breach this year, according to the research firm\u2019s <a href=\"https:\/\/www.comparitech.com\/crypto\/biggest-cryptocurrency-heists\/\">crypto heist tracker<\/a>. While Nomad connected a variety of blockchain networks, the founder and CEO of AVA Labs, Emin G\u00fcn Sirer, tweeted about the incident and said the AVAX bridge was safe.<\/p>\n<p>\u201cThe Nomad bridge, used by non-Avalanche chains, was hacked today,\u201d G\u00fcn Sirer <a href=\"https:\/\/twitter.com\/el33th4xor\/status\/1554316659187392514?s=20&amp;t=GDrzzaMqIVrpKsucMamXIA\">wrote<\/a>. \u201cNomad was the official bridge for EVMOS (Cosmos EVM), Moonbeam (Polkadot EVM), and Milkomeda (another EVM) \u2014 The Avalanche Bridge is unaffected.\u201d<\/p>\n<h2>Nomad Raised $22 Million in April, Blockchain Security Company Certik Says This Particular Bug \u2018Would Be Difficult to Discover Under Conventional Auditing Practices\u2019<\/h2>\n<p>The attack against the Nomad bridge follows the project raising approximately <a href=\"https:\/\/www.businesswire.com\/news\/home\/20220414005497\/en\/%C2%A0Nomad-Announces-22.4-Million-Seed-Round-to-Build-More-Secure-Cross-Chain-Interoperability\">$22.4 million<\/a> in seed funding in a finance round led by Polychain Capital. Other strategic investors that helped Nomad raise funds include 1kx, Ethereal Ventures, Hack.vc, Circle Ventures, Amber, Robot Ventures, Hypersphere, Figment, Dialectic, Archetype, and Ledgerprime. While a broad audit could have found the Nomad bridge vulnerability, the blockchain and smart contract auditors from Certik say this attack may be more difficult to find in a conventional audit.<\/p>\n<p>\u201cThis type of issue would be difficult to discover under conventional auditing practices that assume all deployment configurations are correct, because this particular bug was introduced by mistakes in the deployment parameters,\u201d Certik\u2019s report on the Nomad situation concludes. \u201cHowever, a broader auditing process and full-scope penetration test that includes validating deployment processes would potentially capture this bug,\u201d the auditors added.<\/p>\n<div class=\"article__body__tags-related__tags\">\n<h6 class=\"article__body__tags-related__title\">\nTags in this story<br \/>\n<\/h6>\n<div class=\"article__body__tags\"><a href=\"https:\/\/news.bitcoin.com\/tag\/22-million\/\">$22 Million<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/amber\/\">Amber<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/archetype\/\">Archetype<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/bridge\/\">Bridge<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/bug\/\">bug<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/certik\/\">certik<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/certik-auditors\/\">Certik Auditors<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/certik-audits\/\">Certik Audits<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/circle-ventures\/\">Circle Ventures<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/comparitech\/\">Comparitech<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/comparitech-researchers\/\">Comparitech researchers<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/cross-chain-bridge\/\">cross-chain bridge<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/cross-chain-bridge-hacks\/\">Cross-Chain Bridge Hacks<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/crypto-heist\/\">crypto heist<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/defi-vulnerability\/\">defi vulnerability<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/defi-vulnerabilty\/\">defi vulnerabilty<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/dialectic\/\">Dialectic<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/emin-gun-sirer\/\">Emin G\u00fcn Sirer<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/exploit\/\">Exploit<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/figment\/\">Figment<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/hypersphere\/\">Hypersphere<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/ledgerprime\/\">Ledgerprime<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/nomad\/\">Nomad<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/nomad-bridge\/\">Nomad Bridge<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/nomad-cross-chain-bridge\/\">Nomad cross-chain bridge<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/nomad-theft\/\">Nomad theft<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/robot-ventures\/\">Robot Ventures<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/stolen-crypto\/\">Stolen Crypto<\/a>, <a href=\"https:\/\/news.bitcoin.com\/tag\/third-largest-heist\/\">Third Largest Heist<\/a><\/div>\n<\/div>\n<p><em><strong>What do you think about the recent cross-chain exploit against the Nomad bridge? Let us know what you think about this subject in the comments section below. <\/strong><\/em><\/p>\n<div class=\"article__body__author\">\n<div class=\"article__body__author__avatar\">\n<img src=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg\" srcset=\"https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-150x150.jpg 1x, https:\/\/static.news.bitcoin.com\/wp-content\/uploads\/2018\/04\/2Khomers-300x300.jpg 2x\" class=\"avatar avatar-150 photo\"\/><\/div>\n<div class=\"article__body__author__info\">\n<h6 class=\"article__body__author__info__name\">\nJamie Redman <\/h6>\n<p class=\"article__body__author__info__about\">\nJamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,700 articles for Bitcoin.com News about the disruptive protocols emerging today.<br \/><span class=\"td-social-icon-wrap\"><br \/>\n<a target=\"_blank\" href=\"https:\/\/twitter.com\/jamieCrypto\" title=\"Twitter\" rel=\"noopener\"><br \/>\n<i class=\"td-icon-font td-icon-twitter\"\/><br \/>\n<\/a><br \/>\n<\/span>\n<\/p>\n<\/div>\n<\/div>\n<p class=\"images_credits\"><em><b>Image Credits<\/b>: Shutterstock, Pixabay, Wiki Commons, Comparitech, <\/em><\/p>\n<div class=\"disclaimer\">\n<p><strong>Disclaimer<\/strong>: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. <a href=\"https:\/\/bitcoin.com\">Bitcoin.com<\/a> does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.<\/p>\n<\/div>\n<div class=\"bottom_article_widgets\">\n<aside id=\"bn_widget_spacing-18\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-21\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>More Popular News<\/span><\/h4>\n<\/aside>\n<aside id=\"bn_widget_spacing-19\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-46\" class=\"widget_text td_block_template_1 widget widget_custom_html\"\/>\n<aside id=\"bn_widget_spacing-20\" class=\"td_block_template_1 widget widget_bn_widget_spacing\"\/>\n<aside id=\"custom_html-30\" class=\"widget_text td_block_template_1 widget widget_custom_html\">\n<h4 class=\"block-title\"><span>In Case You Missed It<\/span><\/h4>\n<\/aside>\n<\/div>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script>(function(d, s, id) {\n        var js, fjs = d.getElementsByTagName(s)[0];\n        if (d.getElementById(id)) return;\n        js = d.createElement(s); js.id = id;\n        js.src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&version=v3.2\";\n        fjs.parentNode.insertBefore(js, fjs);\n    }(document, 'script', 'facebook-jssdk'));<\/script><br \/>\n<br \/><a href=\"https:\/\/news.bitcoin.com\/cross-chain-bridge-nomad-loses-190-million-making-it-2022s-third-largest-crypto-heist\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) On Monday, the cross-chain token bridge Nomad was attacked and hackers managed to siphon $190 million from the protocol, draining a great majority of the funds. The Nomad cross-chain bridge attack was the third-biggest crypto heist of 2022, and the ninth largest of all time. Nomad Cross-Chain Bridge [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":13426,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/13425"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=13425"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/13425\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/13426"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=13425"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=13425"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=13425"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}