Nomad Bridge hack — August 2022
Incident facts
| Date of incident | |
|---|---|
| Target type | Cross-chain bridge |
| Loss | $190,000,000Price at time of incident |
| Method | Contract logic errorA routine upgrade set the trusted Merkle root to zero, so every message verified |
| Chains | Ethereum |
| Outcome | Partially recovered |
What happened
The Nomad bridge was drained of about $190m on 1 August 2022 in an incident that is unusual less for its size than for how many people took part.
During a routine upgrade, Nomad initialised the trusted Merkle root to zero. Because zero was also the value the contract used for an unproven message, every message submitted to the bridge was treated as already proven. Any user could withdraw assets they had never deposited.
After the first attacker demonstrated the exploit, the transaction was copied. Hundreds of addresses replaced the recipient with their own and repeated it. More than 300 addresses took funds over roughly an hour, with analysis indicating that 41 of them accounted for about 80% of the total. At least six addresses appeared to act as whitehats, taking funds specifically to return them.
That structure makes the aftermath hard to summarise in a single recovery figure: returns arrived from many parties over months rather than as one event, so no consolidated recovered amount is recorded here.
Sources
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Nomad Bridge hack — August 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/nomad-bridgehttps://itokenly.com/hacks/nomad-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.