Nomad Bridge 2022 message verification exploit
In August 2022, Nomad Bridge was exploited after a message verification flaw made fraudulent withdrawals copyable by many participants. Public reporting commonly describes the loss as roughly $190 million, with partial recovery and unresolved recovery/reimbursement questions.
Incident facts
- Incident title
- Nomad Bridge 2022 message verification exploit
- Bridge
- Nomad Bridge
- Incident date
- 2022-08-01
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, Avalanche, Unknown
- Affected assets
- ETH, USDC, USDT, WBTC
- Attack category
- Message Verification Failure
- Reported loss
- $190 million
- Amount confidence
- Medium
- Loss amount basis
- Public Reports And Secondary Summaries
- Recovery
- Partial Recovery
- Reimbursement
- In Progress
- Restart
- Partially Reopened
- Current outcome
- Limited After Incident
- Postmortem
- Full
- Resolution
- Unresolved
- Last reviewed
- 2026-06-15
- Last verified
- 2026-06-15
Amount and valuation
Reported as roughly $190 million in public coverage.
Public reports commonly cite approximately $190 million; exact recovered and outstanding amounts require later source-specific expansion.
about $190 millionabout $190 million
Used as the display loss amount in this seed record.
Why this remains unresolved
- Only a pro-rata share of recovered assets was made available through the recovery bridge.
- Final recovery and reimbursement completion remain unresolved.
Timeline events
Partial recovery reported2022-08
Nomad documented returned funds and a recovery process intended to make recovered assets available to affected users on a pro-rata basis.
The later restricted bridge relaunch is recorded separately.
Nomad exploit disclosed2022-08-01
The Nomad Bridge exploit became public after fraudulent withdrawals were copied by many participants.
Nomad published root-cause analysis2022-08-05
Nomad documented the initialization and message-verification flaw that allowed fraudulent messages to be accepted.
Nomad recovery bridge relaunched with restrictions2022-12-20
Affected users could bridge back madAssets and access pro-rata recovered funds, while new canonical-token deposits remained disabled.
The relaunch did not restore unrestricted new deposits.
Nomad included in bridge-hack research context2025-01-06
Later cross-chain bridge hack surveys use Nomad as a major reference case for message verification and bridge exploit classification.
Used for context only, not as a primary incident source.
Evidence records
- Crypto bridge Nomad loses $190 million in 'chaotic' hackThe Verge · Tier 2 · High reliability · secondary · 2022-08-02Claim scope: Incident Case
Used for initial public loss framing and chaotic-copycat characterization.
- Nomad cross-chain bridge loses nearly $200 million in exploitCointelegraph · Tier 2 · Medium reliability · secondary · 2022-08-02Claim scope: Amount
Secondary public report used to support approximate loss scale.
- Nomad Network rekt database referenceRekt · Tier 3 · Medium reliability · secondary · 2022-08-02Claim scope: Recovery
Used only as a lower-tier recovery/context reference in this seed record.
- SoK: A Review of Cross-Chain Bridge Hacks in 2023arXiv · Tier 2 · Medium reliability · secondary · 2025-01-06Claim scope: Incident Case
Research context for bridge-hack classification and Nomad as a reference case.
- Nomad Bridge Hack: Root Cause AnalysisNomad · Tier 1 · High reliability · primary · 2022-08-05Claim scope: Incident Case
Primary technical root-cause analysis.
- The Road to RecoveryNomad · Tier 1 · High reliability · primary · 2022-09-22Claim scope: Recovery
Primary description of recovery and reimbursement planning.
- Nomad Bridge Relaunch GuideNomad · Tier 1 · High reliability · primary · 2022-12-20Claim scope: Restart
Primary source for the restricted recovery-oriented relaunch.
- Nomad Bridge Hack: Root Cause AnalysisNomad · Tier 1 · High reliability · primary · 2022-08-05Claim scope: Incident Case
Event-scoped primary copy supporting the Nomad exploit case and unsafe message-verification condition.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The final recovery percentage for each affected asset is not established.
- Long-term operation beyond the recovery-oriented bridge flow requires continued review.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.