Nomic Vulnerability Causes 36% Loss in Osmosis allBTC Collateral

Снимок-экрана-—-2026-09-09-в-15.06.24.png

The Cosmos ecosystem has faced a major security challenge: approximately 36% of the backing for the Alloyed BTC (allBTC) token on Osmosis, a leading decentralized exchange (DEX), was compromised. The cause was the minting of unbacked (phantom) nBTC tokens resulting from an exploit on the Nomic network.

Despite the significant reserve deficit, the Osmosis core team reacted swiftly. Crucially, Osmosis itself and the underlying Inter-Blockchain Communication (IBC) protocol were not compromised—the vulnerability existed solely on the Nomic bridge side.

Below is a detailed breakdown of how the attacker exploited the system, laundered the stolen funds, and how the community plans to restore pool parity.

Background: How Nomic and allBTC Work

To understand the mechanics of the exploit, it is necessary to examine the architecture of the affected assets:

  • Nomic is a Layer-1 blockchain acting as a decentralized bridge. It enables native Bitcoin (BTC) to be brought into the Cosmos ecosystem as a wrapped token, nBTC. By design, every minted nBTC should be strictly backed 1:1 by real Bitcoin locked on the bridge side.
  • allBTC (Alloyed BTC) is an innovative Osmosis mechanism designed to consolidate liquidity. Instead of trading different wrapped Bitcoin variants separately (e.g., WBTC, nBTC, etc.), Osmosis unifies them into a single allBTC pool. Users can deposit any supported version of the asset and swap them at a 1:1 ratio.

Attack Anatomy: Routing Bug and Double-Spending

According to official developer statements, the critical vulnerability stemmed from a transaction routing mechanism bug within the Nomic network itself.

This software flaw allowed the attacker to execute a classic double-spend scheme. The attacker tricked the bridge smart contracts into recognizing unbacked Bitcoin deposits, causing Nomic to generate and release phantom nBTC tokens into the Cosmos ecosystem.

Holding these unbacked nBTC tokens, the attacker routed them into the allBTC pool on Osmosis. Because the pool automatically treats all deposited assets at parity (1:1 ratio), the attacker easily swapped the phantom tokens for legitimate, high-value assets, including other wrapped Bitcoin variants and stablecoins.

Timeline: The Attack and Fund Laundering

An in-depth analysis of the incident was conducted by independent on-chain researcher Rarma. Blockchain data reveals that the attack was not a single event, but unfolded across several stages over several weeks.

Phase 1: Minting and Transfer (June 25)

The core attack occurred in late June. Exploiting the bug in Nomic, the attacker generated 40.65 nBTC. To avoid immediate suspicion, the attacker split this amount and transferred it to Osmosis across 25 separate cross-chain transactions.

Phase 2: Conversion and Exfiltration from Cosmos

Once on Osmosis, the hacker began liquidating the stolen funds through the allBTC pool:

  1. A portion of the phantom tokens was swapped for liquid assets—Wrapped Bitcoin (WBTC) and the USDC stablecoin.
  2. Using cross-chain bridges Axelar and Noble, the hacker exfiltrated these funds from Cosmos to the Ethereum network.
  3. On Ethereum, the assets were converted into Ether (ETH).

Phase 3: Covering Tracks via Tornado Cash

Rarma tracked approximately 671.75 ETH reaching the attacker’s final address on Ethereum. To sever the link between addresses and hide the origin of the funds, the attacker funneled 671.1 ETH (roughly equivalent to 18 BTC) into the Tornado Cash privacy mixer.

Phase 4: Dormant Assets (July 17)

Notably, the attacker did not withdraw the entire balance. The remaining 22.65 nBTC were converted into allBTC on July 17 and left dormant at an address on Osmosis.

Damage Assessment: allBTC Pool Metrics

MetricAsset Volume
Total allBTC Supply~110.57 tokens
Actual Collateral (Healthy Assets)~70.73 BTC
Total Pool Deficit~39.84 BTC (approx. 36%)
Successfully Exfiltrated & Laundered~18 BTC (~671.1 ETH)
Frozen on Attacker’s Osmosis Account~22.65 BTC (as allBTC)

Emergency Response and Recovery Plan

Upon confirming the discrepancy and the presence of 39.84 phantom nBTC in the pool collateral, Osmosis developers and security response teams suspended key operations on September 7:

  • Nomic network operations were halted.
  • Deposit and withdrawal operations via the Nomic bridge were suspended.
  • All deposits and redemptions for allBTC were frozen to prevent further liquidity drain.

Freezing the Attacker’s Funds

Leveraging the Proof-of-Stake architecture and community coordination, the Osmosis team worked alongside network validators to execute an emergency network upgrade. This allowed them to forcibly freeze the attacker’s wallet containing 22.65 BTC.

Closing the Deficit

The DEX developers presented a clear two-step plan to restore 100% collateralization for allBTC:

  1. Seizure: A proposal will be submitted to the Osmosis Decentralized Autonomous Organization (DAO) to officially seize the 22.65 BTC frozen in the hacker’s account and return it to protocol reserves.
  2. Treasury Compensation: The remaining deficit (~17.19 BTC, which the hacker successfully laundered through the mixer) will be covered using funds from the Community Pool.

If approved by the DAO, allBTC collateral will be fully restored, ensuring regular pool users suffer no financial loss.

This incident highlights that cross-chain bridges remain a major vulnerability in decentralized finance (DeFi). However, the rapid coordination among Osmosis validators to deploy an emergency patch, paired with the project’s commitment to cover losses via its community treasury, demonstrates the resilience and maturity of the Cosmos ecosystem when handling crisis scenarios.

scroll to top