LumChain

Market Prices

Coin Price 24h
BTC Bitcoin
$76,389.5 +0.53%
ETH Ethereum
$2,434.47 +1.26%
SOL Solana
$99.83 +2.56%
BNB BNB Chain
$723.1 +1.60%
XRP XRP Ledger
$1.3 +0.50%
DOGE Dogecoin
$0.0808 +1.16%
ADA Cardano
$0.1979 +1.75%
AVAX Avalanche
$7.54 +3.70%
DOT Polkadot
$1.02 +6.62%
LINK Chainlink
$11.14 +3.10%

Fear & Greed

50

Neutral

Market Sentiment

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$76,389.5
1
Ethereum
ETH
$2,434.47
1
Solana
SOL
$99.83
1
BNB Chain
BNB
$723.1
1
XRP Ledger
XRP
$1.3
1
Dogecoin
DOGE
$0.0808
1
Cardano
ADA
$0.1979
1
Avalanche
AVAX
$7.54
1
Polkadot
DOT
$1.02
1
Chainlink
LINK
$11.14

🐋 Whale Tracker

🟢
0x36f6...fd5a
30m ago
In
3,128.32 BTC
🔵
0x50b0...7ce4
12h ago
Stake
2,254,677 USDC
🔴
0x3e8c...14e8
5m ago
Out
48,138 SOL

💡 Smart Money

0x5d3e...b7c8
Experienced On-chain Trader
+$0.2M
90%
0x162e...1c68
Early Investor
+$2.8M
88%
0xa458...b131
Early Investor
+$0.4M
61%

🧮 Tools

All →
Companies

Nomic's Dead Bridge Minted 40.65 BTC From Nothing — The 74 Days Nobody Noticed Is the Real Story

CryptoAlpha

Hook

On June 25, someone minted 40.650602 BTC on Osmosis. There is no bitcoin behind it. No deposit. No custodian. No chain reorg to blame. Just two independent bugs stitched together inside Nomic's custom forwarding mechanism, and a forged attestation that Osmosis's pools accepted as collateral.

Osmosis didn't say a word until September 9. That's 76 days by my arithmetic; the official framing rounds it to 74. Either number is absurd. A 40 BTC hole sat inside a live DeFi liquidity hub for two and a half months, and the asset it contaminated was still being priced and pooled the entire time.

I've spent eleven years watching bridges die. Most die loudly — a flash loan, a drain, a headline. This one died slowly, quietly, and right on schedule, because the people who built it had already walked away two years earlier. We didn't need a new exploit class to explain it. We needed someone to notice.

Context

First, orientation on the cast. Nomic isn't a household name, and that's part of the story. It was one of several attempts to bring BTC into Cosmos as a native asset — a bet that bitcoin holders would move size into DeFi if the wrapping were trust-minimized. The bet half-worked. Assets flowed. Maintenance didn't follow.

Nomic issues nBTC, a Cosmos-native representation of BTC, and routes those representations through IBC rails into venues like Osmosis. Osmosis is the liquidity hub of the ecosystem — where assets go to find a market. allBTC is the Osmosis-side asset that emerges when nBTC gets absorbed into the chain's routing and pooling logic.

The trust assumption was simple on paper: one nBTC, one bitcoin, held in reserve. Everything downstream inherits that assumption. When it breaks, the derivative doesn't merely lose value — it loses meaning. It becomes a claim on nothing.

Here's what the disclosure doesn't lead with. Nomic's GitHub hasn't seen a commit in roughly two years. Its X account went dark in 2024. This is not a team that got hacked mid-sprint. This is a bridge that was already a ghost when the attacker walked through the front door.

Core

Let me be precise about the mechanism, because the mechanism is where the lesson lives.

The attacker combined two separate vulnerabilities. Neither one alone gets you free bitcoin. Together, they let a fabricated credential survive validation. Nomic's custom forwarding mechanism — the bespoke logic that moves attestations across the bridge — is where the exploit landed. The attacker used it to mint 40.650602 nBTC against zero backing, then pushed a forged attestation into Osmosis.

Here's the detail that reframes the whole incident: IBC was not broken. Osmosis's core contracts were not broken. The standardized, heavily-forked, adversarially-tested interchain protocol did exactly what it was designed to do. What failed was non-standard logic that one team wrote, maintained briefly, then abandoned. Standardized rails accumulate hostile attention and get hardened. Custom forwarding logic accumulates documentation debt and gets forgotten.

I've audited enough bridge code to recognize the pattern. When I was reverse-engineering early StarkWare whitepapers back in 2021, what struck me was how much security depended not on cleverness but on how many hostile eyes had already read the same lines. Nomic's forwarding mechanism never got that treatment. Whatever audit existed almost certainly predates the final commits by years — audit drift, the widening gap between "this code was reviewed" and "this code is the code."

Why 74 days? Because composite exploits don't announce themselves. Single-point vulnerabilities surface through TVL anomalies — a pool drains, a number moves, an alert fires. A forged attestation that survives validation looks, from outside, like legitimate bridge traffic. It doesn't spike. It doesn't glitch. It adds supply that shouldn't exist to a system with no independent way to verify it. The detection surface for a correct-looking lie is far smaller than for an obviously broken one. We didn't build for that.

The 40.65 nBTC then did what contaminated assets always do: it flowed downstream. Osmosis pools absorbed it, routed it, repackaged it. The number that should be on every Cosmos risk desk's whiteboard this week is this — 36% of allBTC is now unbacked. Not undercollateralized. Not trading at a discount. Unbacked.

Somewhere in that flow, 22.65 allBTC landed in a wallet the attacker controlled. Osmosis executed an emergency upgrade and froze it. The rest — roughly $1 million, 671 ETH — went through Tornado Cash. That money is gone. Not "possibly recoverable." Gone.

Do the arithmetic the governance proposal quietly does. Freeze the 22.65. Subtract it from the ~40 BTC hole. You're still short something north of 17 BTC, and that shortfall has to come from somewhere. Osmosis's answer: the community pool, plus canceling a planned liquidity deployment for USDC.noble.

The community pool is not a war chest. It's a budget — funded by inflation, earmarked for grants, incentives, public goods. Draining it to backstop a bridge nobody maintains converts one operator's failure into a protocol-wide tax. And the tax falls hardest on people who never touched nBTC, never held allBTC, never knew Nomic existed. That's the mechanism nobody has put a number on yet.

This isn't isolated. Across the same window, Across, Allbridge, and TeleSwap were all hit. Four bridges, one season. Either we're in an attack window, or we're in an inventory-clearance window, where a decade of half-maintained bridge code finally meets attackers who read it more carefully than its authors did. I lean toward the second. Bridges aren't hacked because they're targets. They're hacked because they're maintenance debt with a TVL number attached.

Expect the repricing to be lumpy, not linear. The market learned about a June 25 loss on September 9. We didn't get a shock. We got a backlog. When disclosure arrives 74 days late, the first question a desk asks isn't "how big was the hole," it's "what else hasn't been disclosed yet." That question doesn't get answered by this article or by Osmosis's. It gets answered by whatever the next bridge disclosure turns out to be — which is why the trust hit lands on the whole Cosmos safety premium, not just on OSMO.

Contrarian

Everyone will frame this as a bridge hack. It isn't. It's a lifecycle failure that happened to have a hack attached.

Regulation didn't fail here. Regulation was never in the room. What failed was monitoring — and monitoring is a choice protocols make while they're still alive. A 40 BTC mint with zero corresponding BTC deposit should trip an alarm in any bridge running real-time proof-of-reserve. It didn't, for 74 days. That isn't a clever attacker. That's an absent operator.

The uncomfortable second-order point: Nomic is not special. It's the visible case. Across Cosmos and beyond, bridges that lost their maintainers in 2023 and 2024 still carry user assets on their books. Nobody decommissioned them. Nobody migrated the liquidity away. The composability that makes modular ecosystems powerful is the same property that lets a dead component keep poisoning a live one. Osmosis — the hub — had no defensive posture toward its upstream at all. No health check. No intake due diligence. No automatic flag when a counterparty went silent for twenty-four months.

There's a quieter problem inside the remedy. Governance froze 22.65 allBTC via emergency upgrade and is now proposing to confiscate it. That's a decentralized protocol exercising a centralized power — seizing a balance because a vote said so. Legally, that's a live wire. If the holder surfaces and challenges it, the question becomes whether a token-weighted vote constitutes lawful authority to dispose of someone's property. Institutional desks use exactly this ambiguity to justify staying off a chain entirely.

And the disclosure itself deserves scrutiny. KiiChain's public complaint — that Cosmos Labs pushed the fix before notifying downstream — means some readers got the vulnerability and the remedy in the same breath. That isn't disclosure. That's a race condition on someone else's money.

Takeaway

Watch the governance vote, not the price chart. If the community pool absorbs the shortfall, the precedent is set: bridge failures are now an OSMO liability. If it doesn't, allBTC faces depeg pressure and the remaining 64% gets tested by a run.

The real question isn't how much was lost. It's how many other abandoned bridges are still on the books — and who checks them before the next ghost mints. Because the alternative is that the next one runs the same play: mint against nothing, route downstream, wait out the disclosure lag, let a community pool eat the difference. The tooling to stop that isn't exotic — proof-of-reserve, mint alerts, and a rule that a bridge with no commits in a year loses its asset listing. None of it requires new cryptography. All of it requires that someone, somewhere, is still watching.