The Free-For-All Drain: How a Trusted-Root Bug Let Anyone Empty Nomad Bridge of $190M
Nomad Bridge lost $190 million in liquidity over roughly two and a half hours in an exploit that, unlike most hacks, required no special access or sophistication — once the flaw was discovered, anyone could copy the attack and take a share. It became the 100th incident logged on rekt.news's leaderboard.
Word of the vulnerability spread quickly once the first exploit landed, and a crowd of opportunistic actors piled in behind it. Cross-chain bridges have repeatedly proven to be high-value, high-risk targets in DeFi, and when they fail, the failure tends to be near-total — Nomad's total value locked collapsed essentially to zero.

The fallout extended well beyond Nomad itself. Chains that relied on the bridge for liquidity — Moonbeam, EVMOS, and Milkomeda — all saw their TVLs drop sharply as the assets bridged through Nomad became unbacked. Notably, several participants in the free-for-all have since claimed to be acting as whitehats, and it remains to be seen how much of the drained value will ultimately be returned. With four of the top five entries on the leaderboard now being cross-chain exploits, Nomad's own slogan — "the future of cross-chain communication is optimistic" — reads uncomfortably.
The root cause: A routine upgrade to the bridge in June left its Replica contract initialized with a critical flaw: the zero address (0x00) was set as a trusted message root. As a result, any message evaluated against that root would be treated as automatically valid.
The first attacker's exploit transaction followed a failed initial attempt that had burned roughly $350,000 in gas. The successful version called the bridge's process() function directly, skipping the step of proving message validity altogether. That function governs execution of every cross-chain message and includes an internal check (line 185) meant to verify a merkle root before proceeding. Because of the botched upgrade, any transaction carrying a "messages" value of zero — which older logic would have rejected — was instead interpreted as matching the trusted 0x00 root, and therefore treated as "proven."
That meant every call to process() passed validation regardless of its actual legitimacy. A technically skilled attacker could have written a single contract to drain the entire bridge alone. Instead, what followed was far messier: copycats simply pulled up the original transaction on Etherscan, swapped in their own wallet address, and resubmitted it.
The result was a chaotic blend of crowdsourced hacking spread by word of mouth, scrambling whitehat activity, and MEV bots racing each other to the funds. One participant, known as 🍉🍉🍉.eth, extracted around $4 million and has said they intend to return it as a whitehat. Others were less cooperative: the Rari Capital (Arbitrum) exploiter from April reappeared here, walking away with nearly $3 million in stablecoins that were funneled directly into Tornado Cash.
Among the many exploiters involved, the three largest addresses collectively took roughly $95 million:
0x56D8B635A7C88Fd1104D23d632AF40c1C3Aac4e3 — $47M
0xBF293D5138a2a1BA407B43672643434C43827179 — $40M
0xB5C55f76f90Cc528B2609109Ca14d8d84593590E — $8M
A complete list of exploiter addresses has been compiled and shared publicly.
Warning signs missed: Nomad had undergone a Quantstamp audit in June, and issue QSP-19 from that audit foreshadowed a closely related vulnerability. The auditor's note that "we believe the Nomad team has misunderstood the issue" points to a broader pattern reflected in the project's own "Long-Term Security" documentation.

The team's response to the live exploit also drew criticism for its pace: an official acknowledgement didn't arrive until roughly three hours after the attack began. The bleeding was eventually stopped by removing the Replica contract's owner privileges, but by then the funds were already gone.
This is not the only bridge under strain. The Harmony chain remains unresolved following its own $100 million bridge loss in late June, an attack that investigators have linked to the Lazarus Group.
The knock-on effects continue to show up in TVL figures: Moonbeam's TVL fell from $300 million to $135 million, EVMOS's from around $7 million to $3 million, and Milkomeda's from $31 million to $20 million. The reputational damage from this loss of confidence may ultimately outweigh the direct $190 million loss itself.
Building reliable cross-chain infrastructure remains one of the hardest problems in an already experimental industry, and bridge failures tend to spread damage across every ecosystem connected to them. With this incident marking the 100th entry on the rekt.news leaderboard, it adds one more costly lesson to a growing list — while liquidity, ever mobile, continues moving toward the next opportunity regardless of the risks left behind.
Get new scam files the moment we publish them — usually 2–3 emails a week.