Skip to content

Nomic Exploit Exposes the Extra Trust Behind Bridged Bitcoin

An exploit in Nomic’s custom forwarding mechanism allowed an attacker to double-spend nBTC and send false vouchers to Osmosis, according to Osmosis. The incident did not compromise Bitcoin itself, Osmosis or the Inter-Blockchain Communication protocol, but it affected the backing of a Bitcoin-linked asset used on Osmosis.

The distinction matters for users evaluating bridged BTC. A token can track Bitcoin’s value while depending on additional software, validators, accounting and governance that native BTC does not require.

What Osmosis disclosed

Osmosis said 39.84 nBTC from the exploit sat within Alloyed BTC, representing about 36% of that asset’s backing. Moderation subDAOs paused inflows and outflows involving Nomic and Alloyed BTC after the issue was identified.

Validators also performed an emergency upgrade that froze 22.65 BTC in the attacker’s address. A freeze is not the same as completed recovery. Moving or reallocating those assets requires whatever technical and governance authority applies to the chain, and Osmosis said it would seek governance approval to seize the frozen amount.

The proposed recovery has two parts

Osmosis said it planned to ask governance to use the frozen assets and BTC accumulated in the community pool to cover the remaining shortfall and restore full backing to Alloyed BTC. That proposal would shift part of the loss to collectively controlled resources rather than leave holders with an underbacked asset.

Governance can coordinate a remedy, but it also reveals a trust assumption. Users depend on participants having enough authority to stop flows, upgrade software and potentially redirect assets during an emergency. Those controls can limit damage; they are also different from holding BTC under Bitcoin’s own consensus rules.

Where the failure occurred

Osmosis located the bug in a custom forwarding mechanism on Nomic. False vouchers reached Osmosis because the source-side process accepted value that should not have been represented twice. Osmosis explicitly said its own chain and IBC were not compromised.

That boundary prevents an inaccurate conclusion that every IBC transfer was vulnerable. It does not eliminate the impact on users who treated nBTC or Alloyed BTC as equivalent to native Bitcoin. Cross-chain assets inherit the security of each component involved in custody, minting, message handling, redemption and emergency administration.

What holders should verify

Users should first identify which asset they hold. Native BTC, nBTC and Alloyed BTC are not interchangeable from a security or redemption perspective even when their quoted prices are similar. They should check whether deposits, withdrawals or swaps remain paused and rely on official governance and chain updates rather than unsolicited recovery messages.

Anyone affected should avoid signing approvals offered through social-media replies or direct messages. Real recovery should not require revealing a seed phrase. Holders should preserve transaction hashes and wallet records, monitor whether backing is restored, and understand whether any redemption path depends on a governance vote or software upgrade.

The broader security lesson

Wrapped and bridged assets add utility by moving Bitcoin-denominated value into other applications. They also add failure modes. A sound review asks who controls minting, how deposits are proven, whether liabilities are observable, who can pause or upgrade the system, and how a deficit would be allocated.

The Nomic incident is therefore not evidence of a Bitcoin protocol failure. It is evidence that a Bitcoin representation can be only as reliable as the full bridge and governance system supporting it.

Sources & further reading