Nomic Exploit Leaves $3.15M Gap in Osmosis Alloyed BTC After Unnoticed nBTC Double Minting
For seventy-four days, 40 BTC worth of forged nBTC remained within Osmosis’s Alloyed BTC pool, counted as genuine collateral throughout that period (Protos report).
Nomic generated nBTC using a flawed ibc_deliver function, successfully sending it over a legitimate IBC connection to Osmosis (Rarma analysis). The allBTC transmuter treated it as authentic, exchanging it 1:1, and IBC relayed these packets as usual.

Osmosis, by design, accepted nBTC as equivalent to BTC collateral. However, the vulnerability stemmed from Nomic: Osmosis stated that a bespoke forwarding feature on Nomic enabled a double-spend of nBTC, which let an attacker issue fraudulent vouchers to Osmosis (Osmosis statement).
According to Rarma’s investigation, Nomic’s ibc_deliver created nBTC twice for a single incoming deposit within one block, all for a minimal one-satoshi IBC fee.
By the time the reserves were scrutinized, Nomic’s operations had ceased, its reserve was down to 0.746 BTC, and its GitHub repository had been inactive for two years.
The incident resulted in a $3.15 million shortfall in Osmosis’s Alloyed BTC (Blockfence analysis).
Osmosis was able to freeze 22.65 BTC-equivalent after the attacker abandoned the allBTC position, but the remaining funds had already been moved via cross-chain swaps and ultimately funneled through Tornado Cash (Rarma trace), making recovery highly unlikely.
All messages sent from Nomic were cryptographically valid, but the underlying Bitcoin was missing.
Was anyone verifying the actual collateral?
Credit: Protos, Osmosis, Rarma, Johnny Wyles, Blockfence, Ray Raspberry, Sunny Aggarwal, Trail of Bits
The discrepancy remained undetected for seventy-four days. According to Protos, neither Nomic nor Osmosis made any public announcement during that window.
Discovery of the exploit coincided with the halt of Nomic’s blockchain, prompting Osmosis to review its own reserves.
Rarma’s analysis notes that the untouched 22.650608 allBTC position had not moved since July 17.
Twenty-five identical IBC packets—all for the same value—were identified, all originating from a single Nomic transaction and arriving at Osmosis in the same block on June 25 (transaction link).
Nomic’s social media was inactive after 2024.
The chain halted with the last Nomic block occurring at 15:30:21 UTC on September 7, according to Rarma’s timeline.
Bitcoin checkpointing had already stopped nearly a full day earlier, even though blocks continued to be produced.
Osmosis governance documents confirm that Nomic’s chain halt triggered a review which revealed that only 0.746 BTC remained in reserve for 40.650602 nBTC minted without actual Bitcoin support.
Reportedly, 39.839746 nBTC of the unbacked issuance was held within the allBTC transmuter.
Rarma released a public forensic report on September 8, noting that allBTC was only 63.97% collateralized. Osmosis followed with its own public statement the next day (Osmosis statement).
A third-party researcher published comprehensive forensic findings before Osmosis made its own public disclosure. Nomic remained silent throughout.
What does “quick response” mean if independent researchers reveal the facts before protocol teams do?
Double Mint via ibc_deliver
Osmosis attributed the vulnerability to a custom forwarding mechanism.
Rarma’s analysis pinpoints the flaw in Nomic’s ibc_deliver function.
The function first minted nBTC for the intended amount, then routed it into burn_coins_execute, and minted the same amount again. The second minting was allocated to the destination, making it available for use.
So, two mints occurred for one delivery: the initial coin was consumed, while the second appeared as spendable nBTC at the recipient.
The June 25 transaction produced 25 send_packet events, each for 162,602,409,537,873 µsat, adding up to 40.65060238 nBTC.
Rarma’s report locates all 25 arrivals in Osmosis block 64,910,685, over channel-6897, delivered via six relayer transactions.
The IBC_FEE_USATS was set to 1,000,000, or one satoshi (Rarma source). Rarma’s reconciliation estimates approximately 0.0388 BTC-equivalent was lost to slippage, relayer fees, and gas during cross-system transfers.
No flaws in IBC itself were exploited. Osmosis confirmed IBC was not breached; the issue lay in a bug in Nomic’s custom forwarding mechanism, enabling double-spending of nBTC and the issuance of illegitimate vouchers to Osmosis. Both chains processed the packets per their protocol rules.
The root problem was upstream: Nomic’s custom forwarding minted nBTC without real BTC collateral.
Osmosis’s remediation plan notes that on June 25, Nomic created 40.650602 nBTC with no BTC behind it, across 25 identical IBC packets in a single transaction.
Next, the question became: where did these coins go?
Distribution Through Alloyed BTC
The 25 nBTC packets from the June 25 fraudulent mint reached Osmosis within minutes.
Subsequent actions split along two tracks.
Rarma’s transaction-level investigation determined that about 18 nBTC-worth was converted and routed out through various systems. The remaining 22.65060847 nBTC underwent allBTC conversion on July 17.
That position stayed unaltered until Osmosis froze it on September 7.
Mint Transaction: BEE54496B351A018D092779FE6C833238E1CDF965FE9761A572934F37932E028
Osmosis packet recipient / frozen allBTC position: osmo1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vtzltn
Nomic’s halted state and limited explorer made address-level tracking difficult.
The sender of all 25 outbound IBC packets was nomic1kq2rzz6fq2q7fsu75a9g7cpzjeanmk685ak9g7 to the above Osmosis address.
Rarma identified nomic1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8cgz4wt as the transaction’s signer.
Osmosis then froze 22.650608 allBTC in the corresponding address via emergency upgrade v31.1.0 (recovery proposal).
The same account identifier was present across multiple chains:
Noble: noble1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vny890
Axelar: axelar1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8q788kq
Ethereum beneficiary in Rarma's trace: 0x8f36fd9ffc0a8ca373aa7a4787292536a489d2b5
Rarma traced the flow from these Cosmos addresses to the Ethereum beneficiary.
Within nine minutes of the June 25 Nomic mint block, the Osmosis recipient began swapping the forged nBTC through Pool 1868, the allBTC transmuter.
Rarma described the pool as a near 1:1, no-slippage conversion route among allBTC assets. Initial nBTC-to-WBTC conversions and bridge-outs happened within about fifteen minutes; further outflows occurred later that night and on June 28.
Rarma’s timeline lists the following Osmosis-side activity:
June 25, 21:59:14 UTC - 1.0 nBTC to 1.0 WBTC.eth.axl via Pool 1868: FE5383D9586D0F416686B0D6EA35B40E189391A63EA77E2EE5698E7E217E47A1
June 25, 22:02:46 UTC - 7.0 nBTC to 7.0 WBTC.eth.axl via Pool 1868: F218AA3055284DED74587B212CDF00EEA4F7BAED821844BDAFE43047078D1301
June 25, 22:11:27 UTC - 8.0 WBTC.eth.axl sent via IBC through Axelar GMP to Squid Router contract on Ethereum: 468D435D4705105362DB6BEABFB98852156998A1973CBAA146E1737AC637EE82
June 25, 22:12:35 UTC - 10.0 nBTC to 10.0 WBTC.eth.axl via Pool 1868: 4F1DBB779AEF8ADAEACE65381FDB053120CDB6BE35E7EB81EDA752D3ADBAB96F
June 25, 22:14:21 UTC - 1.5 WBTC.eth.axl sent via IBC through Axelar GMP to Squid Router contract on Ethereum: EF6FFD3034E32DC52B04262681E10311F1EBA626BA0CE7510992963387A30794
June 25, 22:28:53 UTC - 0.29880120 WBTC.eth.axl to 8.097670262686151 ETH.axl: DBCA034646E2A9690D03FD8E753E85C58206ED0DDE5E2A52E69A6D4424F99A81
June 25, 22:29:53 UTC - 8.097670262686151 ETH.axl sent via IBC through Axelar GMP to Squid Router contract on Ethereum: F879A15766BED480F913E74888F572574D88F603CE2EEC97E67946C2A4A1D1D7
June 25, 23:24:58 UTC - 1.99940004 allBTC to 112,509.461495 USDC, sent via IBC to Noble: 65BD688B63AA6E3EC99E6D3F781086CB85243934E1BF15592ECAB8A73698BE8E
June 28, 18:33:44 UTC - 6.16296736 WBTC.eth.axl sent via IBC through Axelar GMP to Squid Router contract on Ethereum: 70DFD62F6DC370C25EDD726CF87BCDB3F668E9049AC88B46E6C7E15C0E182904
July 17, 22:44:35 UTC - 22.65060846827203 nBTC to 22.65060846 allBTC via Pool 1868: 8305D3D413AB95576A5DB59F2AA7F4315ED2386BE0A803F290990263021E8D7E
Mintscan event logs verify the USDC swap and outbound IBC packet to Noble: 1.99940004 allBTC spent, 112,509.461495 USDC received, and Noble address as the receiver.
Noble Receiver: noble1wq76r2mhqsa9yaygghuwyq4wy6dcsgf8vny890
This allBTC balance remained static after July 17 (Rarma’s trace).
Osmosis subsequently froze 22.650608 allBTC at the linked address using the validator-led emergency upgrade v31.1.0.
Rarma tracked the Axelar-routed WBTC through four GMP calls to SquidRouter as the Ethereum target contract, with the Ethereum beneficiary encoded in the payload.
Ethereum Beneficiary: 0x8f36fd9ffc0a8ca373aa7a4787292536a489d2b5
ETH amounts tracked:
These receipts were not visible through standard token transfer scans; Rarma identified them via debug_traceTransaction, which reveals internal calls.
Rarma followed the USDC transfers through Noble and Circle’s CCTP.
Noble Burns:
Both named the same Ethereum beneficiary, and Rarma traced the USDC minted to 71.14822656 ETH via 1inch Fusion.
Across both paths, the trace shows the beneficiary received 671.75412248 ETH, of which 671.10 ETH went to the Tornado Cash router (Tx details), in 34 deposits: 439.10 ETH on June 25 and 232.00 ETH on June 28. At the cited snapshot, 0.5753708194 ETH remained.
Tornado Cash Activity: Beneficiary address
Rarma’s analysis found the only pre-exploit funding for the beneficiary was a small deposit (0.03729586 ETH) on June 22, originating from an address-poisoning bot, followed by a counterfeit token from a lookalike address 24 seconds later. There were no prior exchange or mixer deposits.
One address circulated as “the exploiter”: Nomic1rk07saqmvfle50h4h9hul00g67xzrcc5ytfxjm
Note: Due to Nomic’s unavailability, verification of this address was not possible at the time of review.
Osmosis’s recovery proposal states 18 BTC was extracted and laundered through Tornado Cash. The remaining 22.650608 allBTC remained in an address that could later be frozen.
Given a 39.839746 BTC deficit, the freeze secures roughly 56.9% of the shortfall, leaving about 17.19 BTC still unaccounted for.
Freezing the unmoved funds cannot reverse what has already passed through Tornado Cash.
Does freezing such addresses recover the assets or merely offer a claim to the leftovers?
The Aftermath and Governance Response

Osmosis’s recovery plan involves four steps, some needing further governance action before execution.
First, it proposes cancelling a pending USDC.noble-to-allUSDC liquidity redeployment, unlocking around 7.75 BTC for the Community Pool. 4.7053 BTC would address the residual re-peg deficit, while the remaining ~3 BTC would support wide liquidity between 40,000 and 160,000 USDC.
Second, it allocates 12.4838 allBTC from the community pool to the Liquidity subDAO.
Third, it authorizes use of the frozen 22.650608 allBTC, but notes that a separate upgrade is required to move these funds.
A minor controversy arose during the emergency measures.
The Osmosis Foundation swapped roughly 9 BTC of its allBTC exposure into WBTC hours before the pool was frozen, leading to speculation about foreknowledge.
The Foundation explained this was part of a coincidental test with Bitglobal and published a timeline to support its account. Regardless, the timing necessitated clarification.
Nomic also faces a separate deficit: approximately 0.797700 nBTC from the fraudulent minting never entered allBTC and thus falls outside the proposed recapitalization.
The same proposal notes Nomic’s entire remaining BTC reserve is 0.746 BTC, almost matching the external float but insufficient for redemption.
With the chain halted, redemption is not possible from either side.
Nomic’s Twitter and release history went silent after 2024 (release history). Public GitHub activity stopped as of October 31, 2024, months before the exploit.
In November 2024, Trail of Bits concluded a ten-week security review of Nomic, covering deposit, withdrawal, and IBC transfer logic.
The audit found robust authentication and access controls, no critical issues, and only one medium-severity finding.
The report highlights the limitations of point-in-time audits. Trail of Bits noted that relevant code had changed before their review, but the updated logic was not included in their scope, preventing independent verification.
Comparing ibc_deliver’s two available source snapshots underscores this:
- Commit 809092f: ibc_deliver handled IBC transfer memos as BTC withdrawal requests, minting nBTC a second time only when a withdrawal failed.
- Commit 3dccaf5: ibc_deliver interprets the memo as a general destination, burns nBTC credited to a temporary receiver, mints nBTC outside the failed-withdrawal path, and routes the value through bitcoin.insert_pending. The sender field is set to Identity::None, and a TODO is left regarding sender handling.
The implementations are significantly different. The Trail of Bits review only applies to the code present during their engagement, not to later changes seen at 3dccaf5.
No public source documents an independent review of the later ibc_deliver rewrite. This absence does not prove a review didn’t occur, but it is missing from the public record.
If an audit covers an earlier version but the relevant logic changes substantially, how reliable is that “audited” status?
Neither Bitcoin, IBC, nor Osmosis itself was compromised (Osmosis statement).
A rewritten forwarding function on an inadequately monitored chain minted approximately 40 BTC worth of nBTC without corresponding Bitcoin, and this gap went undetected for seventy-four days (Rarma’s analysis, Protos report).
By the time it was caught, the liquid assets had traversed multiple chains, been converted to ETH, and laundered through Tornado Cash.
The remaining balance was visible and queryable on-chain the entire time.
Osmosis has outlined a plan to restore holders, most of which depends on a governance vote that remains pending.
Nomic is left with a separate unresolved 0.7977 BTC on a halted chain with no redemption path.
The audit targeted the correct file, but not the version that was ultimately exploited for $3.15 million.
The audit was accurate at the time—a snapshot. The mistake was assuming that snapshot remained accurate after the code was changed.
If less than two years and one rewrite is all it takes for an audit to become outdated, how many cross-chain protocols are running on unchecked code snapshots?
Get new scam files the moment we publish them — usually 2–3 emails a week.