E Amazings
  • Home
  • Automotive
  • Business
  • CBD
  • Crypto
  • Education
  • Entertainment
  • Fashion
  • Finance
  • Health
  • Home Improvement
  • Law \ Legal
  • News
  • Shopping
  • Sports
  • Technology
  • Travel
  • Need Help?

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

What Closing Costs Do Home Buyers Have?

February 25, 2023

What Is Realtek HD Audio Manager

February 2, 2023

A Basic Guide To Cell Tower Leasing

February 2, 2023
Facebook Twitter Instagram
E Amazings
  • Home
  • Automotive
  • Business
  • CBD
  • Crypto
  • Education
  • Entertainment
  • Fashion
  • Finance
  • Health
  • Home Improvement
  • Law \ Legal
  • News
  • Shopping
  • Sports
  • Technology
  • Travel
  • Need Help?
Facebook Twitter Instagram
E Amazings
You are at:Home»Crypto»Nomad Bridge Suffers $190M Loss in Chaotic Copy-Paste Attack
Crypto

Nomad Bridge Suffers $190M Loss in Chaotic Copy-Paste Attack

By August 2, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter Pinterest WhatsApp Email

[ad_1]

In the early hours of August 2, Nomad bridge posted an alert that it was aware of an ongoing exploit. In the following hours, the entire protocol’s funds of more than $190 million were drained.

Crypto community developer and white hat ‘samczsun’ broke down the chain of events, explaining what happened. He labeled the attack as “one of the most chaotic hacks that Web3 has ever seen.”

1/ Nomad just got drained for over $150M in one of the most chaotic hacks that Web3 has ever seen. How exactly did this happen, and what was the root cause? Allow me to take you behind the scenes 👇 pic.twitter.com/Y7Q3fZ7ezm

— samczsun (@samczsun) August 1, 2022

Nomad is a token bridge for cross-chain transfers between Ethereum, Avalanche, Milkomeda, and Moonbeam.

Nomad Funds Drained

Researchers shared a tweet in the ETHSecurity Telegram channel showing multiple transactions of funds leaving the bridge. At first glance, it appeared to be a misconfiguration in token decimals, but samczsun discovered:

“However, after some painful manual digging on the Moonbeam network, I confirmed that while the Moonbeam transaction did bridge out 0.01 WBTC, somehow the Ethereum transaction bridged in 100 WBTC.”

What makes this exploit different is that the transactions were not ‘proved’ and executed directly. “Being able to process a message without proving it first is extremely Not Good,” said samczsun. The coder did some more digging and found a fatal flaw in the ‘Replica’ smart contract initialized during a routine Nomad upgrade.

He added that this was chaotic because the crypto thieves did not need any technical knowledge. They just needed to find a transaction that worked, replace the target address with their own, and rebroadcast it.

“A routine upgrade marked the zero hash as a valid root, which had the effect of allowing messages to be spoofed on Nomad. Attackers abused this to copy/paste transactions and quickly drained the bridge in a frenzied free-for-all,”

TVL to Zero

Nomad has even discovered fraudulent addresses attempting to steal funds returned to the bridge.

We’re aware of impersonators posing as Nomad and providing fraudulent addresses to collect funds. We aren’t yet providing instructions to return bridge funds. Disregard comms from all channels other than Nomad’s official channel: @nomadxyz_

— Nomad (⤭⛓🏛) (@nomadxyz_) August 2, 2022

According to DefiLlama, Nomad’s total value locked has crashed from $190.38 million to $5,336 over the past few hours.

Nomad is the latest token bridge attack this year following the high-profile exploits of the Ronin Bridge, Wormhole, and Harmony.

SPECIAL OFFER (Sponsored)

Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.



[ad_2]

Source link

Related Posts

Report With an Eye on Mutual Settlements with China, Russia To Launch CBDC Early Next Year: Report

By September 28, 2022

China Cracks Down a $5.6 Billion Crypto Money-Laundering Scheme (Report)

By September 28, 2022

Binance Launches Training Program For Law Enforcement Agencies

By September 28, 2022

FTX US President Brett Harrison Steps Down

By September 27, 2022
Add A Comment

Comments are closed.

Our Picks

What Closing Costs Do Home Buyers Have?

By Corbin BowenFebruary 25, 2023

What Is Realtek HD Audio Manager

By Corbin BowenFebruary 2, 2023

A Basic Guide To Cell Tower Leasing

By Corbin BowenFebruary 2, 2023
Recent Posts
  • What Closing Costs Do Home Buyers Have? February 25, 2023
  • What Is Realtek HD Audio Manager February 2, 2023
  • A Basic Guide To Cell Tower Leasing February 2, 2023
  • Air Duct Repair 101: Everything You Need To Know February 2, 2023
  • Advantage LIC? How Budget Insurance Amendment Bill may benefit the PSU insurance giant January 5, 2023
  • The Flight Of The Dremel January 5, 2023
  • LIC offering multiple benefits on premium payment with co-branded credit cards with Axis Bank: Check features, offer January 5, 2023
Archives
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • September 2021
Facebook Twitter Instagram Pinterest TikTok
© 2022 E Amazings - All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.