Nomic - Rekt

Forty BTC of counterfeit nBTC sat inside Osmosis's Alloyed BTC for seventy-four days, counted as real collateral the entire time.
Nomic minted nBTC through a vulnerable ibc_deliver path, and it crossed a valid IBC connection to Osmosis. The allBTC transmuter exchanged it 1:1; IBC relayed the packets Nomic emitted.
Osmosis treated nBTC as BTC-equivalent collateral under its design. The failure sat upstream: Osmosis said a custom forwarding mechanism on Nomic allowed an attacker to double-spend nBTC and send false vouchers to Osmosis.
Rarma’s reconstruction says Nomic’s ibc_deliver function minted nBTC twice for one incoming deposit, in a single block, at a one-satoshi IBC fee.
By the time anyone checked the backing, Nomic had gone dark, its reserve down to 0.746 BTC, its GitHub silent for two years.
The result: A $3.15 million hole in Alloyed BTC.
Osmosis froze 22.65 BTC-equivalent after the attacker left that allBTC position idle; the rest had already moved through cross-chain conversion and into Tornado Cash, and pulling it back from there is a long shot.
Every message Nomic sent was cryptographically genuine. The Bitcoin behind it wasn't.
So who exactly was watching for the difference?

Seventy-four days passed before the discrepancy was discovered. Protos reported that neither Nomic nor Osmosis publicly disclosed it during that period.
The exploit only came to light because Nomic's chain halted. That halt is what sent Osmosis digging through its own holdings.
Rarma's reconstruction says the remaining 22.650608 allBTC position had not moved since July 17.
It identifies 25 identical IBC packets, each for the same amount, originating in one Nomic transaction and arriving on Osmosis in a single block on June 25th.
Nomic's Twitter account has not posted since 2024.
Then Nomic halted. Rarma's trace places its final block at 15:30:21 UTC on September 7.
It says Bitcoin checkpointing had stopped 23 hours and 39 minutes earlier, while the chain continued producing blocks.
The Osmosis governance proposal says Nomic's September 7 halt led Osmosis to check Bitcoin backing, revealing 0.746 BTC of reserve against 40.650602 nBTC minted without Bitcoin backing.
The proposal says 39.839746 nBTC of that unbacked issuance was inside the allBTC transmuter.
It also says validators used emergency upgrade v31.1.0 on September 7 to freeze 22.650608 allBTC that the actor had not moved or sold.
Rarma published a public forensic trace on September 8, opening with the finding that allBTC was 63.97% backed.
Osmosis later issued its own public incident statement the next day.
The public record shows an outside researcher publishing a detailed forensic account before Osmosis issued its public incident statement. Meanwhile, Nomic remains silent.
What does "rapid response" mean when an outside researcher publishes a detailed forensic account before the protocol's own public incident statement?
Two Mints, One Delivery
Osmosis calls it a custom forwarding mechanism. That phrase is doing some quiet work.
Rarma’s reconstruction identifies the function as Nomic’s ibc_deliver.
Mint nBTC for the requested amount. Pass that coin into burn_coins_execute. Mint the same amount again.
The second mint was credited to the delivery instruction’s destination as spendable nBTC.
Two mints. One delivery. The first coin is consumed. The second becomes spendable nBTC at the destination.
The June 25 transaction produced 25 send_packet events, each for 162,602,409,537,873 µsat, totaling 40.65060238 nBTC.
Rarma’s trace places all 25 arrivals in Osmosis block 64,910,685, over channel-6897, through six relayer transactions.
Rarma says the code set IBC_FEE_USATS to 1,000,000, one satoshi. Its fund-flow reconciliation separately estimates that roughly 0.0388 BTC-equivalent was lost to slippage, relayer fees, and gas as the proceeds moved through other systems.
None of this required breaking IBC. Osmosis said IBC was not compromised; it attributed the incident to a bug in Nomic’s custom forwarding mechanism that allowed the attacker to double-spend nBTC and send false vouchers to Osmosis.
IBC delivered packets Nomic had emitted and Osmosis accepted under the chains’ normal protocol rules.
The failure sat upstream: Nomic’s forwarding path created nBTC without corresponding Bitcoin backing.
Osmosis’s remediation proposal says that, on June 25, the Nomic bridge minted 40.650602 nBTC with no Bitcoin behind it across 25 identical IBC transfers in a single transaction.
Once those coins existed, where did they go?
Out Through the Alloy
The 25 nBTC packets tied to the counterfeit June 25 mint reached Osmosis within minutes.
What happened next split into two paths.
According to Rarma's transaction-level reconstruction, roughly 18 nBTC-worth was converted and routed out through other systems.
Rarma traces the remaining 22.65060847 nBTC to an allBTC conversion on July 17.
The resulting position then remained dormant until Osmosis froze it on September 7th.
Mint Transaction: BEE54496B351A018D092779FE6C833238E1CDF965FE9761A572934F37932E028
Osmosis packet recipient / later frozen allBTC position: osmo1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vtzltn
Nomic is halted, and its available public explorer has limited address-level visibility.
The surviving transaction record lists nomic1kq2rzz6fq2q7fsu75a9g7cpzjeanmk685ak9g7 as the sender of all 25 outbound IBC packet transfers to the Osmosis address above.
Rarma's reconstruction identifies nomic1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8cgz4wt as the transaction signer.
Osmosis subsequently froze 22.650608 allBTC in the corresponding Osmosis address through emergency upgrade v31.1.0, according to its recovery proposal.
The same 20-byte account identifier appears in addresses on several chains.
Noble: noble1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vny890
Axelar: axelar1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8q788kq
Ethereum beneficiary in Rarma's trace:
0x8f36fd9ffc0a8ca373aa7a4787292536a489d2b5
Rarma's trace follows the proceeds from those Cosmos addresses to that Ethereum beneficiary.
About nine minutes after the June 25th Nomic mint block, the Osmosis recipient began converting the counterfeit nBTC through Pool 1868, the allBTC transmuter.
Rarma describes the pool as a nominal 1:1, no-slippage conversion path between allBTC constituents.
Rarma's trace places the initial nBTC-to-WBTC conversions and bridge-outs within roughly fifteen minutes; other exits followed later that night and again on June 28th.
Rarma's trace records the following Osmosis-side sequence as follows…
June 25, 21:59:14 UTC - 1.0 nBTC to 1.0 WBTC.eth.axl through Pool 1868: FE5383D9586D0F416686B0D6EA35B40E189391A63EA77E2EE5698E7E217E47A1
June 25, 22:02:46 UTC - 7.0 nBTC to 7.0 WBTC.eth.axl through Pool 1868: F218AA3055284DED74587B212CDF00EEA4F7BAED821844BDAFE43047078D1301
June 25, 22:11:27 UTC - 8.0 WBTC.eth.axl sent by IBC from Osmosis through Axelar GMP to the Squid Router contract on Ethereum: 468D435D4705105362DB6BEABFB98852156998A1973CBAA146E1737AC637EE82
June 25, 22:12:35 UTC - 10.0 nBTC to 10.0 WBTC.eth.axl through Pool 1868: 4F1DBB779AEF8ADAEACE65381FDB053120CDB6BE35E7EB81EDA752D3ADBAB96F
June 25, 22:14:21 UTC - 1.5 WBTC.eth.axl sent by IBC from Osmosis through Axelar GMP to the Squid Router contract on Ethereum:
EF6FFD3034E32DC52B04262681E10311F1EBA626BA0CE7510992963387A30794
June 25, 22:28:53 UTC - 0.29880120 WBTC.eth.axl to 8.097670262686151 ETH.axl: DBCA034646E2A9690D03FD8E753E85C58206ED0DDE5E2A52E69A6D4424F99A81
June 25, 22:29:53 UTC - 8.097670262686151 ETH.axl sent by IBC from Osmosis through Axelar GMP to the Squid Router contract on Ethereum: F879A15766BED480F913E74888F572574D88F603CE2EEC97E67946C2A4A1D1D7
June 25, 23:24:58 UTC - 1.99940004 allBTC to 112,509.461495 USDC, sent by IBC from Osmosis to noble1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vny890 on Noble: 65BD688B63AA6E3EC99E6D3F781086CB85243934E1BF15592ECAB8A73698BE8E
June 28, 18:33:44 UTC - 6.16296736 WBTC.eth.axl sent by IBC from Osmosis through Axelar GMP to the Squid Router contract on Ethereum: 70DFD62F6DC370C25EDD726CF87BCDB3F668E9049AC88B46E6C7E15C0E182904
July 17, 22:44:35 UTC - 22.65060846827203 nBTC to 22.65060846 allBTC through Pool 1868: 8305D3D413AB95576A5DB59F2AA7F4315ED2386BE0A803F290990263021E8D7E
Mintscan's event logs for that transaction independently establish the allBTC-to-USDC swap and outbound IBC packet to Noble: 1.99940004 allBTC spent, 112,509.461495 USDC in the post-swap IBC action, and an address on Noble named as the packet receiver.
Noble Receiver:
noble1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vny890
That allBTC balance did not move after July 17th, according to Rarma's trace.
Osmosis later froze 22.650608 allBTC in the corresponding address through the validator-operated emergency upgrade v31.1.0.
Rarma traces the Axelar-routed WBTC proceeds through four GMP calls naming SquidRouter as the Ethereum destination contract, while encoding an Ethereum beneficiary in the payload.
Ethereum Beneficiary:
0x8f36fd9ffc0a8ca373aa7a4787292536a489d2b5
The execution path runs through Axelar Gateway, SquidRouter, SquidMulticall, a Uniswap V3 WBTC/WETH pool, WETH unwrapping, and native ETH delivery to the beneficiary.
303.01315917 ETH: 0x75b42eceb283eaa88303d23bca8f9ccc6c5579cdfc1e8c757ea1e33118dd125b
57.09781972 ETH: 0xe051dc2bbb37b1510faecaeace9288ca5bc0deda9562bdfe164643d268e69236
8.09751591 ETH: 0x3dc170230bbbaab36b0bbfb0201ba705d09448be9db973c3725a72577e54ae1a
232.39729801 ETH: 0x6426edf655e833c2544a5541faceadb22d8d7c9a758432b409932155b6b4148f
Those receipts didn't appear in a standard token-transfer scan. Rarma says it identified them through debug_traceTransaction, which exposes the internal contract calls.
Rarma traces the USDC leg through Noble and Circle's CCTP.
Noble Burn 1, 56,254.663934 USDC: 14003B7245C38C55778DA07C77AC123A69711AD95D264EC2F4DDA162985C0CD3
Noble Burn 2, 56,254.623933 USDC: D8FFF6FD4538CA34B0F40AB842E1C67AF1590DA922AF93B29B0475C7C055FF99
Both named the same Ethereum beneficiary as mint_recipient. Rarma traces the minted USDC through 1inch Fusion into 71.14822656 ETH.
Across both routes, Rarma's trace says the beneficiary received 671.75412248 ETH, then sent 671.10 ETH to the Tornado Cash router, across 34 deposits: 439.10 ETH on June 25th, and 232.00 ETH on June 28th. 0.5753708194 ETH remained in the address in Rarma's cited snapshot.
Tornado Cash Movement:
0x8f36fd9ffc0a8ca373aa7a4787292536a489d2b5
Rarma's trace identifies the beneficiary's only pre-exploit funding as 0.03729586 ETH on June 22nd, from an apparent address-poisoning bot, followed 24 seconds later by a counterfeit token from a lookalike address.
The trace found no exchange or mixer deposit into the wallet beforehand, and the funding amount was enough to pay transaction costs.
One address circulated as "the exploiter":
Nomic1rk07saqmvfle50h4h9hul00g67xzrcc5ytfxjm
Editor’s note: Nomic’s chain was unavailable for independent address-level verification at the time of review, so the address above is currently unavailable.
Rarma's review counts about 3,100 transactions on it, all update_client calls for an IBC light client, consistent with a relayer, and says it found no basis to treat it as the attacker.
Osmosis's recovery proposal says 18 BTC was extracted and laundered through Tornado Cash. The remaining 22.650608 allBTC sat in an address that could later be frozen.
Against the proposal's 39.839746 BTC allBTC shortfall, that freeze preserves about 56.9% of the deficit, leaving roughly 17.19 BTC still uncovered.
Freezing the slow money doesn't unwind what already went through Tornado Cash.
So what exactly does a freeze recover, the funds themselves, or just the standing to vote on what's left of them?
Nineteen Months Later
Osmosis's recovery proposal has four moving parts, and at least one depends on a later governance decision that the proposal does not itself execute.
First, it would cancel the pending USDC.noble-to-allUSDC liquidity redeployment, freeing an estimated 7.75 BTC of Community Pool-owned BTC.
The proposal assigns 4.7053 BTC to the residual re-peg gap and would redeploy the roughly 3 BTC remainder into the planned wide liquidity position between 40,000 and 160,000 USDC.
Second, it would allocate 12.4838 allBTC from the community pool to the Liquidity subDAO.
Third, it would authorize use of the 22.650608 allBTC frozen at the attacker-linked address, but the proposal says moving that balance requires a separate software upgrade, the transfer is not self-executing.
Fourth, it would mark nBTC as corrupted in the allBTC transmuter; the Liquidity subDAO would then withdraw the corrupted nBTC against the collateral supplied in steps two and three, and burn it. Once the nBTC balance reached zero and had been removed from the alloy, Osmosis would restore allBTC deposit and withdrawal functionality.
A smaller controversy ran alongside the emergency response.
The Osmosis Foundation converted roughly 9 BTC of its own allBTC exposure into WBTC hours before the pool was paused, timing that raised an obvious question: Did someone know early?
The Foundation's answer was a coincidental test of native WBTC burns with Bitglobal, accompanied by a chronology intended to document that explanation.
Maybe so. The transaction still required an explanation because, absent one, its timing suggested something else.
Nomic's balance sheet carries a smaller, separate hole. About 0.797700 nBTC from the fraudulent issuance never entered allBTC, placing it outside the proposed recapitalization entirely.
The same forum proposal puts Nomic's entire remaining Bitcoin reserve at 0.746 BTC, close to the external float but not enough to cover it.
With Nomic halted, neither side of that equation has a live redemption path.
Nomic's Twitter account went quiet in 2024. Its public release history did too. After that, sustained public communication was hard to find.
Public GitHub activity visible in the repository history appears to end on October 31, 2024, well before the June 2026 exploit.
In November 2024, Trail of Bits published a ten-week security review of Nomic. The engagement covered incoming BTC deposits, outgoing nBTC withdrawals, and transfers of nBTC to native accounts and IBC-compatible chains.
The report rated authentication and access controls as strong, found no critical-severity issues, and identified one medium-severity finding.
The report also illustrates the limits of a point-in-time audit. In its destination-commitment finding, Trail of Bits wrote that Nomic had already changed the relevant code before the review began, but that the updated code was not included in the audited commit.
The auditors could therefore identify the issue in the supplied revision, but could not independently verify the claimed remediation.
The same principle applies when comparing the two available ibc_deliver source snapshots.
At commit 809092f, the function treated the IBC transfer memo as a Bitcoin-withdrawal request. Its second nBTC mint appeared only in the error-handling path, returning funds when that withdrawal could not be completed.
At commit 3dccaf5, ibc_deliver follows a different model. It parses the memo as a general Dest, burns the nBTC credited to the temporary IBC receiver, mints nBTC outside a failed-withdrawal refund path, and routes the resulting value through bitcoin.insert_pending.
The same implementation explicitly assigns the sender field to Identity::None and leaves a TODO, indicating that sender handling remained unfinished.
The two snapshots show materially different ibc_deliver implementations.
The Trail of Bits report supports conclusions about the code revisions in scope during its engagement, not automatically about the memo-directed forwarding, pending-deposit, and sender-handling logic visible in 3dccaf5.
No cited public source documents an independent assessment of the ibc_deliver rewrite at 3dccaf5. That is not evidence that no later review occurred, but it does mean the public record does not show one.
If an audit reviewed an earlier revision of the right file, but the relevant code path was materially rewritten afterward, what is the shelf life of the word “audited”?

Nobody hacked Bitcoin. Nobody hacked IBC. Nobody even hacked Osmosis.
A rewritten forwarding function on a lightly monitored chain minted roughly 40 BTC of nBTC without corresponding Bitcoin collateral, and the discrepancy went unnoticed for seventy-four days.
By then, Rarma's trace shows the liquid proceeds had already crossed chains, converted to ETH, and moved through Tornado Cash.
The slower-moving balance sat in the open the entire time, in a position anyone could have queried, on a ledger anyone could have read.
Osmosis has a plan to make holders whole, most of it contingent on a governance vote that hasn't happened yet.
Nomic has its own unresolved 0.7977 BTC hanging off a halted chain nobody can currently withdraw from.
The audit covered exactly the right file. It just didn't cover the version of it that ended up costing $3.15 million.
The audit wasn't a lie. It was a snapshot. The failure was treating that snapshot as if it stayed true after the code changed.
If nineteen months and one rewrite is all it takes to turn a clean audit into a false sense of security, how many other bridges are still running on a snapshot nobody's checked since?

REKT作为匿名作者的公共平台,我们对REKT上托管的观点或内容不承担任何责任。
捐赠 (ETH / ERC20): 0x3C5c2F4bCeC51a36494682f91Dbc6cA7c63B514C
声明:
REKT对我们网站上发布的或与我们的服务相关的任何内容不承担任何责任,无论是由我们网站的匿名作者,还是由 REKT发布或引起的。虽然我们为匿名作者的行为和发文设置规则,我们不控制也不对匿名作者在我们的网站或服务上发布、传输或分享的内容负责,也不对您在我们的网站或服务上可能遇到的任何冒犯性、不适当、淫秽、非法或其他令人反感的内容负责。REKT不对我们网站或服务的任何用户的线上或线下行为负责。