longbridgelongbridge
  • Platform Features
    Features
    Investment ProductsPrivate Wealth ManagementTrading ToolsMarket Data ServicesAnalysis ToolsNews ServicesFor Developers
    Account Types
    For IndividualsFor Institutions
  • Café
longbridge
© 2026 Longbridge|Terms of ServicePrivacy Policy

Osmosis Took 74 Days To Discover A 40-BTC Nomic Exploit That Left Its Bitcoin-Backed Asset 36% Unbacked

CoinLive
Sep 14, 2026 at 10:22 AM
LongbridgeAII'm LongbridgeAI, I can summarize articles.

Osmosis discovered a 74-day exploit by Nomic that left its allBTC reserves 36% unbacked, with ~40 BTC missing. The attacker minted nBTC without depositing Bitcoin via double-spending bugs. Osmosis froze remaining assets and proposed governance measures to cover the shortfall. The incident highlights security and disclosure concerns within the Cosmos ecosystem.

An attacker minted 40.65 BTC worth of Nomic’s nBTC on June 25 without depositing any Bitcoin to back the tokens. It then took Osmosis — where the resulting shortfall left its allBTC reserves 36% unbacked — 74 days to discover the exploit.

Neither of the Cosmos-based projects appeared to detect or disclose the loss during that period. The exploit only came to light after the Nomic protocol was halted, prompting Osmosis to investigate its holdings and uncover the missing Bitcoin backing.

Recently, we became aware of an exploit on the Nomic chain. The exploit allowed the attacker to double-spend nBTC, allowing them to send false vouchers to Osmosis. Osmosis and IBC were not compromised, as the bug was in a custom forwarding mechanism on Nomic.

39.84 nBTC of the…

— Osmosis 🧪 (@osmosis) September 9, 2026

The incident also raises questions about the state of Nomic itself. The project’s X account has not posted since 2024, while its GitHub repository has reportedly seen no commits for roughly two years, suggesting the protocol may no longer be actively maintained.

The attacker combined two separate bugs to generate a transaction that “minted 40.650602 BTC of nBTC on Osmosis with no BTC behind it.”

For Osmosis, the damage could have been worse. The attacker left a significant portion of the proceeds untouched as allBTC, which the exchange froze earlier this week through an “emergency upgrade.” The exploiter did, however, manage to cash out roughly $1 million worth of the proceeds at the time by converting 671 ETH and sending it to Tornado Cash through Ethereum.

Osmosis now faces a roughly 40-BTC hole in the backing of its allBTC reserves. A proposal on the project’s governance forum outlines a plan to cover the shortfall, including seizing the 22.65 allBTC frozen in the attacker’s account, cancelling a pending liquidity redeployment of USDC.noble and withdrawing additional allBTC from the Community Pool.

The Nomic exploit is also putting the Cosmos ecosystem’s security and disclosure practices under scrutiny.

Osmosis, a decentralized exchange, and Nomic, a bridge, are both part of the wider Cosmos ecosystem, which has recently experienced a series of security incidents stemming from a separate vulnerability in a widely used Cosmos EVM module.

That episode also drew criticism over how the vulnerability was disclosed. Cosmos Labs came under fire after one affected project, KiiChain, described its loss as “avoidable,” arguing that publishing a critical security fix before notifying affected teams effectively “hands the vulnerability to anyone reading the commit.”

POINT OF FAILURE - NOMIC / OSMOSIS

Osmosis and IBC were not hacked. According to @osmosis, a flaw in @nomicbtc enabled nBTC double-spending and fraudulent vouchers.

Reported exposure: 39.84 nBTC in Alloyed BTC. Validators froze 22.65 BTC. RCA and recovery remain pending. pic.twitter.com/FYKwo8kZoL

— Roman | Validator DevOps (@RomanChainOps) September 9, 2026

The Nomic incident presents a different but equally troubling problem. Rather than a vulnerability becoming public before affected projects could respond, an attacker appears to have exploited the flaw and left behind a hole in Bitcoin backing that remained undetected for more than two months.

That delay matters because the longer an exploit remains undiscovered, the more time an attacker has to move, convert or conceal stolen assets — and the harder it becomes for affected projects to determine the full scale of the damage.

For Osmosis, the immediate challenge is filling the missing Bitcoin backing and accounting for the assets that were recovered or moved. For the broader Cosmos ecosystem, the incident raises a more fundamental question: how quickly can projects detect a critical exploit once an attacker has already found it?

Login to unlock3,282characters for free

Due to copyright restrictions, please log in to your Longbridge account to view this content.
Thank you for your understanding and support of licensed content.

Recommended Readings

  • Apr 17, 2026 at 11:00 PMMarkets Watch Iran-US Situation; European Stocks Open Mostly Lower, Netflix Pre-Market Down 10%, Dollar Oscillates at Lo…
  • Apr 16, 2026 at 10:58 PMMythos Sends Global Financial Elites Into Panic and Confusion: Bank of England Governor Asks, 'What Did I Do Wrong in a …
  • Apr 16, 2026 at 04:12 AMGoldman Sachs Files for Bitcoin Covered Call ETF, Wall Street Accelerates Crypto Asset Taming
  • Apr 16, 2026 at 02:11 AM"Perpetual Contracts" with 7*24-Hour Leverage: Crypto Capital Heavily Trades Gold and Oil "Tokens"
  • Apr 14, 2026 at 10:49 PMWarsh Submits Financial Disclosure, Key Step in Fed Chair Confirmation Process

Related Stocks

Grayscale Bitcoin Trust BTC - ETF

Grayscale Bitcoin Trust BTC - ETF

USGBTC

+6.21%

iShares Bitcoin Trust ETF

iShares Bitcoin Trust ETF

USIBIT

Fidelity Wise Origin Bitcoin Fund - ETF

Fidelity Wise Origin Bitcoin Fund - ETF

USFBTC

LongbridgeAI