T
iTokenly

Nomad Bridge hack — August 2022

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeCross-chain bridge
Loss$190,000,000Price at time of incident
MethodContract logic errorA routine upgrade set the trusted Merkle root to zero, so every message verified
ChainsEthereum
OutcomePartially recovered

What happened

The Nomad bridge was drained of about $190m on 1 August 2022 in an incident that is unusual less for its size than for how many people took part.

During a routine upgrade, Nomad initialised the trusted Merkle root to zero. Because zero was also the value the contract used for an unproven message, every message submitted to the bridge was treated as already proven. Any user could withdraw assets they had never deposited.

After the first attacker demonstrated the exploit, the transaction was copied. Hundreds of addresses replaced the recipient with their own and repeated it. More than 300 addresses took funds over roughly an hour, with analysis indicating that 41 of them accounted for about 80% of the total. At least six addresses appeared to act as whitehats, taking funds specifically to return them.

That structure makes the aftermath hard to summarise in a single recovery figure: returns arrived from many parties over months rather than as one event, so no consolidated recovered amount is recorded here.

Sources

  1. ImmunefiSecondary · retrieved 2026-08-01
  2. CertiKSecondary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Nomad Bridge hack — August 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/nomad-bridge
https://itokenly.com/hacks/nomad-bridge

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.