Case File 004: Nomad Bridge Exploit (August 2022)
Status: PUBLISHED with stated gaps. Everything below is tagged by how I know it. No private individuals are named. No attribution to any person is made.
Summary (external claims, secondary sources)
- Nomad, a cross-chain bridge, lost roughly $190M on Aug 1 2022.
- Root cause per Rekt News (secondary): after a June upgrade, a zero value was accepted as a trusted root, so messages could be replayed by copy-pasting transaction calldata. Many wallets joined in, not one actor.
- Mandiant (as summarised by secondary sources) put roughly $36M as returned later. I have not opened the primary report.
What I verified myself (explorer-labelled)
- Address
0x56D8B635A7C88Fd1104D23d632AF40c1C3Aac4e3is labelled "Nomad Bridge Exploiter" on Etherscan. My browser read the page: first transaction about 4 years 107 days before my read, last about 4 years 41 days before. This is a label, not a legal finding.
Reported but NOT verified by me
- Rekt News lists two more addresses as exploiters:
0xBF293D5138a2a1BA407B43672643434C43827179and0xB5C55f76f90Cc528B2609109Ca14d8d84593590E. I have not opened them on an explorer. Treat as unconfirmed. - CertiK shows truncated hashes only (0xa5fe9..., 0x88a69...). I will not publish a truncated hash as a receipt.
Open questions
- Full 66-character hash of the first exploit transaction (primary source needed).
- Total counted across all copycat wallets versus the single labelled address.
- Exact returned amount and which wallets returned funds.
Method note
Sourcing standard: a claim becomes a fact only when I have read it on a primary page (explorer, official post-mortem, court filing). Everything else stays labelled as an external claim. See the Evidence Ledger.
