konversi_timezone(23 Oct 2022 20:58, America/New_York, 'full date') All About Nomad Bridge Hack: Attack of the Copycats
R

All About Nomad Bridge Hack: Attack of the Copycats



Oct 23, 2022  
A small smart contract flaw lets a large number of attackers steal the project's funds. Here's what happened behind the Nomad Bridge hack.

Massive heists continue to pollute the crypto world. Millions of dollars worth of digital currencies have been stolen from crypto firms lately. Strangely, most of those incidents no longer occurred in the same type of firm: DeFi bridges.

From the $540 million Ronin Bridge hack story in March to the $250 million Wormhole Bridge case in February, it's hard to say that it's merely a coincidence. It appears that instead of using crypto exchanges as the main point of attack, these illicit actors now prefer to steal from DeFi bridges.

Bridges refer to the infrastructure that allows users to exchange assets between different blockchains. When a bridge swaps one coin for another, it basically "wraps" the asset so that it will be able to function on the other blockchain. So, every time an investor deposits a coin, the bridge will issue a new token to represent the wrapped coin on a different blockchain. This is why bridges must hold large reserves of various coins to back those wrapped coins. Naturally, such huge coin reserves are attracting hackers and turning DeFi bridges into main targets for crypto attacks.

In the most recent case, hackers reportedly stole nearly $200 million worth of cryptocurrency from Nomad Bridge, a crypto bridge provider that allows users to swap tokens between Ethereum, Avalanche, Evmos, Milkomeda C1, and Moonbeam. Interestingly, the Nomad Bridge case turned out to be quite simple and most of the exploiters were just copycats. What does that mean?

 

The Case of Copycats

The first suspicious transaction occurred at Ethereum block 1525801 on August 1, 2022. The attacker was able to withdraw 100 WBTC from the bridge and later swapped them for WETH and ETH. Not long after, a swarm of copycats joined the party. In just a matter of a few hours, the bridge's wallet balance dropped down from over $190 million to $16.5k. The stolen tokens were mostly USDC, followed by WETH, WBTC, and CQT.

Apparently, those new attackers or 'copycats' had found a way to copy the original hacker's transaction call data. They simply replaced the original address with their own and the transaction would succeed; as easy as CTRL+C, and CTRL+V. As a result, over $186 million of ERC-20 tokens were drained from the Nomad Bridge between August 1 and August 2, 2022.

Nomad first acknowledged the incident on Twitter. According to the tweet, they were "working hard to address the situation". The company has also notified law enforcement and retained leading firms for blockchain intelligence and forensics to help them solve the case. Still, the shock wave was inevitable in the global crypto community.

 

The Root Cause

According to Nomad, the hack was caused by the implementation of a smart contract upgrade called the Replica contract that took place in June 2021. There is a flaw in the system that makes it unable to authenticate messages properly, so any message can be modified as long as it hasn't been processed. As a result, contracts relying on the Replica upgrade for authentication suffered a critical security failure.

The first attacker then took advantage of such a vulnerability by arranging a message that was able to trick the bridge into sending the stored tokens without proper authorization. Once the code is cracked, the rest of the hackers can easily copy the trick and extract the funds to their pockets.

In total, about 88% of the hackers' addresses were identified as copycats. They used a number of variations of the original message by modifying the targeted tokens, amounts, and recipient addresses.

 

The Aftermath

As a result of the system's vulnerability, over $190 million was drained from the Nomad Bridge. On August 3, 2022, the co-founder of Nomad and his team put up a request for the hackers to return the funds to a specific recovery address. Nomad also announced an up to 10% bounty to those who return at least 90% of the funds they exploited and let them keep the rest. The company won't take any legal action either against those who returned the funds.

As of August 9, about 17% of the stolen funds have been returned to the recovery address. Most of the returns happened a few hours following Nomad's request and continued for the next couple of days, although the number slowly began to thin out than when the address was first posted.

What's interesting is that the majority of the returned funds are in USDC, followed by USDT, WBTC, DAI, CQT, and WETH. It is worth noting that the original hackers mostly took WBTC and WBTH. The fact that most of the returned funds came in the form of USDC and USDT suggests that most of the funds came from later-stage copycat hackers.

Hackers who fully send the stolen funds back to the recovery address are referred to as white hats. Some people believe that the white hats only stole the funds because they were trying to protect the funds from malicious actors. Meanwhile, those who only partially send the funds back are called grey hats and those who don't return the funds at all are called black hats.

So far, more than $36 million of the stolen funds have been recovered, thanks to the white hats. The rest of the money either remained untouched or has been moved onward. It's still unclear whether the black hat hackers are just waiting for the heat to die down or they are still holding on for a better bounty from Nomad.

 

Why Hackers are Interested in Bridges

There are several possible reasons why crypto scammers and hackers are so attracted to DeFi bridges lately:

  • Huge profit. As mentioned above, DeFi bridges hold a lot of money, similar to crypto exchanges. Instead of using the traditional social engineering attack and exploiting security design issues, these new hackers tend to target specific software loopholes, as in most bridge hack cases.
  • Easier and cheaper. It's considered easier to use assets that are not native to the network. Bridges allow malicious actors to transfer funds more quickly at a lower cost. They can also get exposure to assets that aren't native to the network while gaining the benefits of the other network.
  • Consolidation. Hackers can combine funds from different networks, which makes the transaction easier to handle and launder onwards. This also adds a layer of complexity to trace the funds, so they can mask their traces a bit better.
  • Access to a wider ion of dApps. Different dApps have different functions, so hackers can get more creative in using various tools when executing their plans.

 

What's Next?

If you were a Nomad client and you had put some funds in the bridge, unfortunately, there's nothing you can do now. The wisest thing to do is to wait for the official instructions from the Nomad team. Some people might message you and promise to return your funds. These are scammers, so do not interact with them.

To prevent losing more money in the future, here are some tips to keep in mind:

  • Understand and stay up to date with the security policies of the protocols that you use.
  • Regularly review any contract approvals that you don't need.
  • When adding liquidity, don't put all of your money in a single protocol or store them all in one bridge.
  • Search up and block crypto addresses that have been involved with illicit activity in the past.
  • Monitor the inputs and outputs of protocols that have been abused by illicit actors before.
  • Work with blockchain intelligence providers to immediately identify when illicit funds have moved from one network to another.

 

The Future of DeFi Bridges

The Nomad Bridge hack is now the fourth largest DeFi hack in history and the third biggest one in 2022, following the Wormhole Bridge hack in February and the Ronin Bridge hack and in March. It seems that crypto hacks have become popular these days, considering that over $1 billion in digital assets have been stolen from the start of 2021 through March of this year. This shows that there are loopholes scattered in the blockchain system, waiting to be discovered by malicious hackers.

The growing number of bridge attack cases only adds to the security concerns within the crypto community. This might explain why crypto markets are often going bearish these days. Although crypto transactions remain popular, there's no guarantee that they will stay that way in the following years.

Nevertheless, one thing to remember is that in every industry, there are always crashes and burns. To some extent, these hacks are even "necessary" to improve the existing security protocols. We can think of it as just a part of the process of building strong and lasting mechanisms.

In order to prevent getting caught in a troublesome hack case and losing money, it's important to take precautionary actions and protect your funds. Don't put all your eggs in one basket to minimize the risks. Lastly, always make sure to put your funds in a reliable company with good security measures.


7 Comments

Case

Oct 26 2022

Could you please provide an explanation of what blockchain is? From the information provided, it seems that bridges play a role in facilitating transactions between different blockchains. Before delving into the specific details of bridges, I would like to have a better understanding of the fundamental concept of blockchain. How does blockchain work, and what are its key characteristics that distinguish it from traditional s or record-keeping systems? Additionally, how does the decentralized nature of blockchain contribute to its security and immutability? Thank you!

Tomoa Hayate

May 31 2023

@Case: Hey there! I will explain little bit shorter about blockchain. The rest you can read at here : Blockchain: The Future of Wire Transfers.

So, in short, Blockchain is a decentralized digital ledger that records transactions across multiple computers. It works by grouping transactions into blocks, which are linked together in a chain. It's different from traditional systems because it doesn't rely on a central authority and is transparent, secure, and tamper-proof. The decentralized nature of blockchain enhances security by eliminating a single point of failure, and consensus mechanisms ensure agreement on valid transactions. This makes blockchain reliable and resistant to fraud. Its transparency and trustless nature allow parties to engage in transactions without intermediaries. Overall, blockchain provides a secure and transparent way to record and verify information.

Ferran

May 18 2023

What I have learned from this article is the following:

  • Firstly, in the realm of cryptocurrencies, a bridge serves as a medium for transferring funds between different cryptocurrencies. Similar to a physical bridge, it facilitates the connection between various elements.
  • Secondly, due to the multitude of crypto transactions taking place on the bridge, it becomes a target for hackers, considering the presence of different currencies involved.
  • Thirdly, the article emphasizes the aspect of fund security. Numerous funds are entrusted to the bridge, but unfortunately, they can be lost due to hacker attacks.
  • Lastly, the article highlights the frequency of bridge attacks, signifying the potential risks involved in storing cryptocurrencies solely on a bridge. It suggests using a crypto wallet as a safer alternative.

Thank you for sharing the article! It has provided valuable insights into the concept of bridges and the associated risks of attacks.

Lidya

May 24 2023

I think the article really opened up my mind about crypto world. In the first, they said crypto is super safe especially from hacker because the blockchain technology. I mean, The blockchain is a decentralized ledger that records all transactions and is maintained by a network of computers known as nodes. The distributed nature of the blockchain makes it difficult for hackers to manipulate or alter transaction records. And the encryption in there really hard to breach. But after reading this article, I think the weak spot in the crypto is when you do the transaction outside the blockchain, I mean they attacked the bridge, right? And the bridge is operated by the service provider, right? So, I want to know, is there any bridge provider that can be considered safe

Hyuga

May 28 2023

@Lidya:  You're absolutely right! The blockchain technology used in cryptocurrencies provides a high level of security due to its decentralized and immutable nature. However, as highlighted in the article, one vulnerability lies in the bridges or connections between different blockchain networks or when interacting with centralized services.

When it comes to bridge providers, it's essential to choose reputable and trusted platforms. Look for providers that have a strong track record, established reputation, and robust security measures in place. Conduct thorough research, read reviews, and consider the transparency and accountability of the provider.

Some well-known bridge providers in the crypto space that I know include Chainlink, Ren Protocol, and Wrapped Bitcoin (WBTC). These platforms aim to enhance interoperability between different blockchains while prioritizing security and trustworthiness.

Jorge

Jun 4 2023

Hey there, beside this bridge attack, I wan to know, when it comes to cryptocurrencies, we often witness significant price drops and market volatility. In such situations, it's important to consider how brokers handle these fluctuations. So, I'm curious to know, in general, what measures or policies brokers have in place to assist traders during periods of cryptocurrency price drops.

For instance, do brokers offer risk management tools or educational resources to help traders navigate turbulent markets and make well-informed decisions? Are there features like stop-loss orders or margin call protection to limit potential losses? Additionally, do brokers provide timely market analysis or updates to keep traders informed about the latest developments in the cryptocurrency space?

Erling

Jun 5 2023

@Jorge: Hey there! That's a solid question, especially when it comes to the crazy ups and downs of cryptocurrencies. Brokers totally get it and they've got your back during those wild price drops.

So, what do brokers do to help you out? Well, they've got some nifty risk management tools to keep your losses in check. One of those tools is the stop-loss order, which lets you set a limit on how much you're willing to lose. If the market goes south, the order kicks in and saves you from big losses. Some brokers even offer margin call protection to prevent your account from going into the negative.

But that's not all! Brokers know that knowledge is power, so they provide educational resources to keep you in the loop. You'll find trading guides, webinars, articles, and all sorts of goodies to help you understand the cryptocurrency market better. They want you to make smart decisions and avoid getting caught off guard.


Coin Price Change
Bitcoin
$63,891.47 1.59%
Ethereum
$3,117.58 0.45%
Tether
$1.00 -0.04%
BNB
$585.85 -0.20%
Solana
$146.14 1.64%
USDC
$1.00 -0.01%
XRP
$0.53 -0.28%
Dogecoin
$0.16 9.59%
Toncoin
$5.75 1.06%
Cardano
$0.46 -0.85%
Exchange Volume
$43,169,896,208
$26,974,367,562
$23,922,727,842
$18,823,386,009
$17,084,567,555
$16,420,330,766
$15,689,450,846
$15,538,010,056
$13,533,915,588
$12,685,200,769
$11,907,707,028
$10,110,854,710
$8,379,600,346
$6,682,456,728
$6,224,157,600
$6,022,755,214
$5,978,796,361
$5,761,454,269
$4,905,371,671
$3,857,087,018
$3,602,729,510
$3,364,770,634
$2,550,798,524
$2,465,651,389
$2,415,405,192
$2,379,571,460
$2,302,998,847
$2,189,395,985
$2,171,283,066
$2,047,812,300
$2,045,479,019
$2,004,597,722
$1,756,974,096
$1,719,687,233
$1,557,028,284
$1,525,025,276
$1,482,575,267
$1,471,388,681
$1,359,782,692
$1,215,055,953
$1,154,150,198
$1,085,508,182
$1,056,841,935
$992,329,018
$987,834,725
$950,652,558
$950,024,361
$937,183,351
$896,944,113
$887,237,877
$882,844,271
$855,907,251
$841,998,701
$820,342,265
$780,951,032
$780,492,829
$747,407,136
$715,369,637
$715,125,150
$696,405,391
$653,738,249
$648,572,023
$647,649,825
$643,573,444
$643,075,019
$640,865,020
$606,075,970
$596,420,955
$593,557,796
$568,276,634
$500,928,798
$496,046,544
$490,435,730
$476,947,443
$474,205,839
$463,527,439
$448,276,407
$436,606,811
$433,939,880
$430,933,783
$428,131,659
$422,005,183
$419,203,069
$385,768,827
$359,059,713
$356,595,518
$352,719,100
$336,928,363
$330,754,312
$326,314,812
$274,794,936
$271,809,668
$261,217,833
$245,566,304
$239,551,331
$232,807,968
$232,453,456
$214,842,488
$204,591,118
$201,356,246
$197,039,066
$195,974,688
$192,173,808
$191,262,506
$189,936,004
$189,437,444
$187,809,846
$179,252,139
$178,547,440
$176,372,238
$173,080,789
$158,272,846
$157,407,174
$157,049,916
$149,987,255
$147,550,098
$144,936,244
$134,351,682
$133,400,953
$127,804,797
$126,387,413
$126,307,643
$125,139,485
$123,374,407
$122,449,042
$120,543,741
$118,473,606
$115,043,538
$113,224,380
$112,629,438
$109,013,817
$106,329,607
$106,326,091
$101,233,508
$100,469,673
$99,002,624
$97,959,636
$97,196,466
$92,567,770
$91,147,890
$85,403,180
$84,990,085
$84,989,791
$84,429,991
$83,982,880
$83,964,207
$82,499,665
$82,270,706
$78,035,419
$77,719,130
$77,107,226
$72,458,561
$69,307,893
$66,303,490
$63,141,924
$60,929,167
$59,195,148
$58,988,028
$57,543,871
$56,813,207
$55,217,752
$54,063,804
$53,234,243
$48,206,064
$48,144,107
$47,551,663
$47,087,215
$46,933,681
$46,149,718
$43,811,270
$43,469,005
$43,109,944
$42,580,174
$42,372,135
$41,728,072
$41,081,782
$39,162,962
$38,987,556
$35,490,574
$32,308,470
$30,740,484
$30,400,231
$29,360,069
$28,937,405
$28,565,294
$28,275,926
$27,242,419
$25,622,929
$23,986,814
$23,730,603
$23,263,781
$23,239,174
$22,393,370
$21,943,817
$21,522,767
$20,427,286
$20,368,594
$20,137,720
$19,671,122
$19,230,410
$18,727,320
$18,696,914
$17,830,248
$17,544,650
$17,217,232
$17,194,904
$16,962,481
$16,891,593
$16,739,356
$15,985,396
$15,670,782
$15,146,675
$15,132,531
$15,064,466
$14,782,395
$14,772,621
$14,541,656
$14,112,889
$14,071,133
$14,009,700
$13,779,287
$13,589,861
$13,539,053
$13,108,802
$12,828,915
$12,557,840
$12,522,218
$12,263,582
$11,887,498
$11,548,327
$11,522,396
$11,117,927
$11,056,846
$10,355,116
$10,255,141
$10,111,708
$9,608,124
$9,531,851
$9,417,487
$9,268,977
$9,163,684
$8,958,794
$8,176,869
$8,039,969
$7,957,536
$7,895,895
$7,632,692
$7,573,366
$7,409,979
$7,320,803
$7,295,907
$7,099,134
$7,067,725
$6,998,090
$6,985,543
$6,852,890
$6,672,040
$6,593,128
$6,280,892
$6,255,702
$6,209,053
$6,176,298
$5,945,167
$5,791,522
$5,573,370
$5,310,612
$5,214,378
$4,934,721
$4,922,566
$4,347,516
$4,337,884
$4,018,589
$4,013,907
$3,803,416
$3,748,268
$3,715,224
$3,666,313
$3,659,699
$3,548,302
$3,523,109
$3,456,973
$3,442,930
$3,272,394
$3,258,251
$3,203,120
$3,202,530
$3,136,060
$3,114,791
$3,091,377
$3,083,452
$3,066,096
$3,056,648
$2,956,181
$2,951,120
$2,918,276
$2,871,220
$2,827,862
$2,810,209
$2,797,080
$2,742,102
$2,721,856
$2,701,163
$2,648,597
$2,638,157
$2,620,121
$2,593,162
$2,592,613
$2,588,765
$2,586,828
$2,575,069
$2,518,422
$2,450,152
$2,444,970
$2,416,286
$2,362,196
$2,360,814
$2,353,296
$2,297,340
$2,232,556
$2,223,589
$2,163,130
$2,113,576
$2,109,140
$2,085,771
$2,042,543
$1,987,857
$1,877,229
$1,865,078
$1,842,531
$1,840,237
$1,837,188
$1,814,068
$1,700,118
$1,688,163
$1,666,933
$1,508,027
$1,498,039
$1,495,280
$1,495,024
$1,345,438
$1,281,935
$1,263,660
$1,006,269
$978,948
$929,472
$855,485
$766,149
$595,765
$574,945
$537,592
$522,229
$503,704
$466,416
$371,726
$367,480
$367,354
$352,556
$344,454
$286,762
$286,070
$282,169
$142,027
$124,066
$114,660
$103,016
$102,503
$98,557
$82,779
$70,171
$63,246
$54,235
$39,215
$34,869
$34,020
$21,049
$20,138
$13,186
$8,772
$3,019
$1,954
$1,467
$957
$866
$866
$526
$73
$12
$0
$0
$0
$0
$0
$0
$0
$0
$0
$0
$0
$0
$0
$0
$0