The Nomad bridge hack: how one bad setting let hundreds of strangers drain $190 million
When the Nomad crypto bridge was drained of about $190 million in August 2022, more than 300 different addresses took part, many of them simply copying the first thief's transaction and swapping in their own details.[1] This case file covers how one setup error turned a bank-like vault into a free-for-all, what happened to the money and the people involved, and the one control that would have caught it.
What happened
Nomad ran a bridge: a service that lets people move crypto tokens from one blockchain to another. Users deposit tokens on one side, and the bridge releases matching tokens on the other side once it has checked that the deposit really happened. At any given time, a bridge like this holds a large pool of other people's money.[1]
On Monday, August 1, 2022, that pool started emptying. A first attacker pulled out assets, and within hours others noticed what was working and joined in. By the time it was over, about $190 million in various crypto assets was gone, taken by more than 300 addresses. Just 41 of them accounted for about $152 million, roughly 80% of the total.[1]
Not everyone who took money meant to keep it. At least 6 ethical hackers who grabbed funds to protect them held about $8.2 million and said they would return it.[1] Nomad publicly asked people to send the money back and offered those who did a 10% reward.[3]
How it worked
A bridge's main job is to refuse fake withdrawal requests. Nomad did this by checking each incoming message against a list of trusted reference values, called roots, that stood for deposits it had actually verified.[1]
When a version of the contract was put into service, it was set up so that the value zero was marked as a trusted root. Zero was also what the system used by default for messages that had never been proven at all. The result was that the check quietly passed for everything: any withdrawal request looked as if it had already been verified.[1] Analysts at a blockchain security firm said the code had been deployed without a proper audit.[1]
What made this heist unusual is how little skill it took. Blockchain transactions are public. Once one withdrawal had gone through, anyone could look it up, copy it, replace the destination with their own wallet and send it again.[1][2] No special knowledge was needed, which is why hundreds of unrelated wallets piled in.[2]
How it was caught
There was no hiding the theft; it happened in public view on the blockchain, and security firms were tracing wallets within hours.[1] The harder problem was following the money afterward. Investigators said funds were moved across several blockchains, run through mixing services and converted into harder-to-trace coins.[2]
In May 2025, Israeli authorities arrested a man sought by the United States in connection with the exploit, and Israel later approved his extradition.[2][4][5] According to reports, prosecutors do not say he wrote the exploit but allege he played a central role and helped launder stolen funds.[2] He has been charged, not convicted.
What it cost
About $190 million left the bridge in a matter of hours.[1] Some was handed back by ethical hackers and people who accepted the reward, but much of it was not, and users whose tokens were locked in the bridge were left waiting to learn what they would recover.[1][3]
The missing control
The missing control: testing upgrade defaults before deployment. A new version went live with a starting setting that made the most important safety check pass for everything.
This was not a clever break-in. It was a configuration mistake that a basic pre-launch test would have exposed: submit a withdrawal that was never proven and confirm it is rejected. A checklist that reviews every initial value, especially zeros and blanks, and an independent audit of the change before it went live would have caught the problem before any money was at risk.[1]
What to do in your business
- Test that bad requests fail. Before any change to a system that moves money or grants access goes live, try a request that should be refused and make sure it is.
- Review the defaults. When setting up new software, a new payment tool or a new user account, check what each setting is out of the box. Blank and zero values deserve special suspicion.
- Get a second reviewer for changes. Have someone other than the person who made a change look it over before it goes live, even if that means an outside contractor for a few hours.
- Keep a kill switch. Know how to pause payouts, refunds or transfers quickly if something looks wrong, and who is allowed to pull it.
- Limit what sits in one place. Keep only the balance you need in any single account or wallet that can pay out automatically, so one mistake cannot empty everything.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How a small business keeps software and devices patched, and why default passwords must go
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How WannaCry hit the NHS: the fix existed 2 months before the attack
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- Every patching and monitoring control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- The Block: Nomad's $190 million bridge exploit drew hacking feeding frenzy of 300 addresses
- BleepingComputer: Israel arrests new suspect behind Nomad Bridge $190M crypto hack
- OCCRP: U.S. crypto firm offers hackers bounty after crypto heist
- Decrypt: Israel nabs suspect sought by US over $190M Nomad bridge exploit
- CryptoSlate: Israeli authorities arrest Nomad Bridge hacker, approve extradition to US