ADVERTISEMENT
EGW-NewsA One-Satoshi Bug Just Blew a $3 Million Hole in Osmosis's Bitcoin Fund
A One-Satoshi Bug Just Blew a $3 Million Hole in Osmosis's Bitcoin Fund
216
0
0

A One-Satoshi Bug Just Blew a $3 Million Hole in Osmosis's Bitcoin Fund

An attacker found a flaw in Nomic's bridge code, minted bitcoin that didn't exist, and moved it onto Osmosis. Nobody noticed for 74 days.

Osmosis said on September 9 that its pooled Bitcoin asset, Alloyed BTC, had been running with roughly a third of its reserves missing since late June. The exploit came down to a bug in Nomic's transaction-forwarding code, which let an attacker double-spend nBTC — Nomic's bitcoin-pegged token — and push fabricated deposit vouchers into Osmosis's system as if they were backed by real BTC.

"Recently, we became aware of an exploit on the Nomic chain," the exchange wrote on X. "The exploit allowed the attacker to double-spend nBTC, allowing them to send false vouchers to Osmosis. Osmosis and IBC were not compromised, as the bug was in a custom forwarding mechanism on Nomic."

That last part matters. Nomic is a Cosmos-based bitcoin sidechain, and nBTC is supposed to sit in Osmosis's Alloyed BTC pool at a clean one-to-one ratio with real bitcoin, alongside other wrapped versions like WBTC and cbBTC. The bug wasn't in Osmosis's own contracts or in the Inter-Blockchain Communication protocol that ties Cosmos chains together — it lived specifically in how Nomic handled incoming Bitcoin deposits.

How Cheap Was It

Genuinely cheap. According to the independent researcher known as Rarma, who published a transaction trace and code walkthrough on X before Osmosis's own disclosure went out, the flaw let Nomic register the same bitcoin deposit twice. One copy processed normally. The second became free nBTC, mintable without any bitcoin behind it. Rarma found it in just one of eighteen near-identical deposit-handling routines in the codebase, and the whole thing apparently cost the attacker one satoshi to trigger.

The exploitation itself traces back to June 25 — not September, when Osmosis went public. Over roughly 25 cross-chain transfers, the attacker moved close to 40 nBTC onto Osmosis. That's a slow bleed hiding in plain sight for two and a half months, not a smash-and-grab.

What It Actually Cost

Numbers here vary a bit depending on who's counting and which bitcoin price they're using at the moment. Osmosis put the unbacked amount at 39.84 nBTC, close to 36% of Alloyed BTC's total backing — a shortfall reported around $3.15 million. Osmosis froze 22.65 BTC still sitting at the attacker's address through an emergency validator upgrade, worth somewhere between $1.8 million and $1.9 million depending on the snapshot. That leaves a gap of roughly 17 BTC, or something in the low single-digit millions, that the frozen funds don't cover. None of the write-ups I've seen fully reconcile these figures, and Osmosis hasn't published a line-by-line accounting yet, so treat the exact dollar total as directionally right rather than final.

A One-Satoshi Bug Just Blew a $3 Million Hole in Osmosis's Bitcoin Fund 1

Osmosis has paused minting, redemptions, and new Nomic-related deposits while it sorts this out. Trading of bitcoin-backed assets in existing pools is still live, with a warning attached about elevated risk. Governance is now being asked to approve seizing the frozen 22.65 BTC, along with a top-up from the community pool, to bring Alloyed BTC back to full backing.

The Part That Should Worry People More Than The Dollar Figure

Bridges get hacked constantly — Ronin lost $600 million, Nomad lost $190 million, Harmony's Horizon bridge lost $100 million, and that's just the greatest-hits list from the last few years. Three million dollars barely registers next to those. What's more uncomfortable here is the 74-day gap. A flaw sat in production code, got exploited in small batches, and neither Nomic's team nor Osmosis's monitoring caught it until an outside researcher went looking.

Rarma reportedly found the faulty logic still unpatched in Nomic's development branch as of September 8, the day before Osmosis's public statement. Whether that's now fixed hasn't been confirmed publicly. Nomic's own account hadn't posted a matching disclosure as of this writing, which is its own kind of tell — for an exploit involving your bridge, on your chain, silence reads as either disorganization or an unwillingness to own the failure before the post-mortem is ready.

Don’t miss esport news and update! Sign up and recieve weekly article digest!
Sign Up

I don't think this kills confidence in Cosmos bridging infrastructure on its own. But "custom forwarding mechanism" is doing a lot of work in that Osmosis statement, and it's worth remembering that every bridge project's custom code is exactly where these bugs tend to live — not in the standardized, heavily audited parts of the stack, but in the bespoke glue code nobody stress-tests as hard.

ADVERTISEMENT
Leave comment
Did you like the article?
0
0

Comments

ADVERTISEMENT
FREE SUBSCRIPTION ON EXCLUSIVE CONTENT
Receive a selection of the most important and up-to-date news in the industry.
*
*Only important news, no spam.
SUBSCRIBE
LATER