Nomad hack — August 2022
Incident facts
| Date of incident | |
|---|---|
| Target type | Cross-chain bridge |
| Loss | $186,000,000Published estimates range $186,000,000 to $190,000,000Price at time of incident |
| Recovered | $37,500,000 |
| Method | Contract logic erroran upgrade left the committed Merkle root at bytes32(0), so any unproven message passed the Replica contract's authentication check |
| Chains | Ethereum |
| Audited beforehand | Quantstamp |
| Attributed to | Over 300 addresses participated; Alexander Gurevich charged in the US in connection with the exploitAlleged |
| Outcome | Partially recovered |
What happened
Nomad's token bridge was emptied on 1 August 2022 through an initialisation error introduced in a routine upgrade deployed on 21 June 2022. Nomad's own root cause analysis sets out the flaw: the Replica contract's message authentication was changed to test status with acceptableRoot(), and Replicas deployed alongside their Home contracts were initialised with a committed root of bytes32(0), which set confirmAt[bytes32(0)] = 1. Any message that had never been proven defaulted to that same zero value, so every unproven message passed authentication. No Merkle proof was required.
What followed was unusual in scale. Once the first successful transaction was visible on chain, anyone could copy its calldata, substitute their own address and withdraw. Nomad counted over 300 unique addresses taking part. The bridge held ETH, USDC, WBTC and assorted ERC-20 tokens.
Published figures differ modestly. Nomad's own accounting and the FTC's later complaint both put the loss at about $186 million; TRM Labs says $190 million; early coverage described it as nearly $200 million. Nomad honoured 10 per cent bounty requests from returners. About $37.5 million came back, roughly 20 per cent of the total, which the FTC's December 2025 order requires be distributed to affected customers.
The FTC found Nomad had been warned internally about inadequate testing and deployed the code anyway, and that consumer losses were approximately $100 million. According to the FTC's complaint as reported, the security firm Quantstamp flagged the vulnerability in a June 2022 audit and the Nomad team concluded the auditor had misunderstood the issue. Quantstamp has separately disputed the extent to which the deployed code matched what it reviewed; that dispute is not resolved here.
Law enforcement
Alexander Gurevich, a Russian-Israeli dual national, was arrested in Jerusalem in a coordinated operation involving Israeli police, the US Department of Justice, the FBI and Interpol; Israeli authorities approved his extradition and he faces US federal charges including wire fraud, conspiracy and money laundering (TRM Labs). The amount attributed to him individually is not stated by TRM Labs. In December 2025 the FTC announced an action against Illusory Systems requiring it to return recovered funds and implement an information security programme.
Sources
- Nomad (Illusory Systems)Primary · retrieved 2026-08-01
- Nomad (Illusory Systems)Primary · retrieved 2026-08-01
- US Federal Trade CommissionPrimary · retrieved 2026-08-01
- The Record (Recorded Future News)Secondary · retrieved 2026-08-01
- Hunton Andrews KurthSecondary · retrieved 2026-08-01
- TRM LabsSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/nomad-xyz-blog/nomad-bridge-hack-root-cause-analysis-875ad2e5aacd
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Nomad hack — August 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/nomadhttps://itokenly.com/hacks/nomadPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.