{"investigation":{"slug":"nomad-bridge","entity_name":"Nomad Bridge","trust_score":8,"severity_base":null,"score_modifier":0,"confidence":0.92,"status":"published","content_type":"investigation","summary":"Nomad Bridge, operated by Illusory Systems Inc., was a cross-chain asset bridge that suffered a catastrophic $190 million exploit on August 1, 2022, when a routine smart contract upgrade inadvertently initialized trusted Merkle roots to a zero value, rendering all message proofs automatically valid. The vulnerability enabled a widely replicated 'crowd-sourced' draining event involving approximately 300 addresses over roughly 150 minutes — widely regarded as the first 'permissionless' mass-exploitation event in DeFi history. Subsequent actions include a class-action lawsuit, a December 2025 FTC settlement requiring repayment of approximately $37.5 million to affected users, and the 2025 arrest and extradition of a key suspect, Russian-Israeli national Alexander Gurevich.","sections":[{"content":"Nomad Bridge was a cross-chain messaging and asset bridge protocol developed by Illusory Systems Inc., a Utah-based company incorporated in Delaware on November 10, 2021. The protocol was designed to allow users to transfer assets and messages between different blockchains in a trust-minimized manner. Illusory Systems was co-founded by CEO Pranay Mohan and CTO James Prestwich. In April 2022, the company raised $22.4 million in seed funding led by Polychain Capital, with participation from Circle Ventures, Hack VC, Archetype, Breyer Capital, Figment, and others. The protocol operated on an optimistic verification model using Merkle proofs to validate cross-chain messages. At the time of the exploit, it held approximately $190 million in locked assets across supported chains including Ethereum, Moonbeam, Avalanche, and Evmos.","heading":"Background and Protocol Overview","sources":[{"url":"https://www.classaction.org/news/nomad-crypto-bridge-class-action-says-simple-programmer-mistake-allowed-186m-hack-in-2022","name":"classaction.org","type":"other","credibility":3},{"url":"https://www.crunchbase.com/organization/illusory-systems-inc","name":"crunchbase.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-nomad-hack-august-2022","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The vulnerability arose from a June 2022 upgrade to Nomad's Replica.sol smart contract. During the upgrade, the value of the protocol's trusted Merkle root was initialized to 0x00 — the zero hash. This was significant because 0x00 also represented the default value for unproven message roots within the system's verification logic. As a result, the contract's `_process()` function treated any message bearing a zero-value root as automatically proven, entirely bypassing the Merkle proof validation mechanism that was intended to ensure only legitimate cross-chain messages could trigger fund releases. In practice, this meant an attacker could call the process function directly, specify any recipient address and any token amount, and the contract would honor the request as if a valid proof had been submitted. The initialization choice was described by security analysts as logical in isolation but carrying unforeseen implications for the entire verification system. Halborn Security characterized the root cause as a logic error in the contract upgrade initialization rather than a conventional reentrancy or overflow vulnerability.","heading":"The Exploit: Technical Root Cause","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-nomad-hack-august-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/hack-analysis-nomad-bridge-august-2022-5aa63d53814a","name":"medium.com","type":"other","credibility":3},{"url":"https://nomoslabs.io/blog/nomad-bridge-exploit-technical-breakdown-190m-hack","name":"nomoslabs.io","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit began when an initial attacker discovered the vulnerability and executed the first successful drain transaction — submitting a message requesting 100 WBTC in exchange for only 0.01 WBTC bridged from Moonbeam, receiving the full 100 WBTC on Ethereum. Once this transaction was visible on-chain, the attack required no additional technical sophistication to replicate: any address could copy the original transaction data, substitute their own recipient address, and submit it. Approximately 300 distinct addresses exploited the vulnerability over a span of roughly 150 minutes, making it what analysts described as the first 'permissionless' or 'crowd-looted' exploit in DeFi history. Mandiant's threat intelligence analysis identified four primary attacker groups. Group D, assessed with high confidence as a single actor or coordinated group, stole approximately $54.5 million — the largest share — routing funds through OrionPool, Uniswap, and Curve before sending portions to Tornado Cash. Group B was attributed with moderate confidence to the same actors behind the April 2022 Rari Capital exploit, suggesting some portion of the attack involved experienced smart contract exploiters. In total, 14 addresses each stole more than $2 million.","heading":"Attack Execution: The 'Crowd-Sourced' Drain","sources":[{"url":"https://cloud.google.com/blog/topics/threat-intelligence/dissecting-nomad-bridge-hack","name":"cloud.google.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/160851/nomads-190-million-bridge-exploit-drew-hacking-feeding-frenzy-of-300-addresses","name":"theblock.co","type":"other","credibility":3},{"url":"https://decrypt.co/106459/crypto-bridge-nomad-exploited-190m-frenzied-free-for-all","name":"decrypt.co","type":"other","credibility":3}],"severity":"medium"},{"content":"The total value drained from the Nomad Bridge was approximately $190 million, making it one of the largest DeFi exploits of 2022 and one of the largest cross-chain bridge attacks on record. Following the exploit, Nomad announced a 10% bounty program, offering to refrain from legal action against any exploiter who returned at least 90% of the funds they had taken, and providing a 'Whitehat' NFT as acknowledgment. By August 9, 2022, approximately $32.6 million in assets had been returned by white-hat participants, including $6 million USDC, $2.88 million DAI, and $2.1 million WBTC. Total recovered funds reached approximately $37–37.5 million, representing roughly 20% of the total stolen amount. The FTC's December 2025 settlement with Illusory Systems established that users ultimately lost approximately $100 million after accounting for partial recoveries and the company's own recovery efforts — indicating that neither the bounty program nor subsequent law enforcement actions recovered the bulk of stolen funds.","heading":"Financial Impact and Recovery Efforts","sources":[{"url":"https://cointelegraph.com/news/white-hat-hackers-have-returned-32-6m-worth-of-tokens-to-nomad-bridge","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.cnbc.com/2022/08/05/crypto-startup-nomad-offers-10percent-bounty-after-190-million-hack.html","name":"cnbc.com","type":"other","credibility":3},{"url":"https://www.theregister.com/2025/12/17/nomad_ftc_settlement/","name":"theregister.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In February 2023, a class-action lawsuit was filed in the United States District Court for the District of Delaware against Illusory Systems Inc. and related parties, styled Singh v. Illusory Systems Inc. et al. The complaint alleged RICO violations including wire fraud and operating an unlicensed money-transmitting business, and sought return of funds and monetary damages. On March 29, 2024, the court issued an opinion dismissing the RICO claims; other claims in the suit were also contested by Illusory Systems, which sought full dismissal. In December 2025, the Federal Trade Commission announced a proposed settlement with Illusory Systems under which the company would be required to repay approximately $37.5 million to affected users within one year, implement a comprehensive information security program, assign a dedicated security officer, and submit to regular independent third-party security assessments. The FTC alleged that Nomad had marketed its protocol as 'security-first' while failing to use secure coding practices, implement vulnerability reporting processes, or deploy breach-limiting technologies. FTC Bureau of Consumer Protection Director Christopher Mufarrige stated that the settlement reinforced the principle that companies must take reasonable security measures consistent with their public promises. The proposed order was published in the Federal Register on December 19, 2025 for a public comment period ending January 20, 2026.","heading":"Legal and Regulatory Actions","sources":[{"url":"https://www.classaction.org/media/singh-v-illusory-systems-inc-et-al.pdf","name":"classaction.org","type":"other","credibility":3},{"url":"https://blockchain.bakermckenzie.com/2024/04/08/u-s-court-dismisses-rico-lawsuit-brought-in-connection-with-nomad-bridge-hack/","name":"blockchain.bakermckenzie.com","type":"other","credibility":3},{"url":"https://www.ftc.gov/news-events/news/press-releases/2025/12/ftc-will-require-illusory-systems-return-money-stolen-hackers-implement-information-security-program","name":"ftc.gov","type":"other","credibility":3},{"url":"https://www.federalregister.gov/documents/2025/12/19/2025-23407/illusory-systems-inc-analysis-of-proposed-consent-order-to-aid-public-comment","name":"federalregister.gov","type":"other","credibility":3},{"url":"https://www.theregister.com/2025/12/17/nomad_ftc_settlement/","name":"theregister.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The FBI's San Francisco field office opened a criminal investigation into the exploit, leading to an eight-count federal indictment filed in August 2023 in the Northern District of California. Alexander Gurevich, a Russian-Israeli dual national, was identified as a key suspect alleged to have conspired with others to execute the exploit and launder the resulting proceeds. According to investigators, Gurevich received stolen assets within hours of the August 2022 breach and moved approximately $2.89 million through a layered laundering operation involving Tornado Cash on Ethereum, conversion to privacy coins including Monero and Dash, routing through decentralized exchanges, and movement to offshore accounts linked to shell companies. Gurevich re-entered Israel on April 19, 2025 during the Passover holiday and was ordered to appear for an extradition hearing; he instead legally changed his name in the Israeli Population Registry to 'Alexander Block,' applied for a new passport, and attempted to flee to Russia on May 1, 2025. He was arrested at the airport before departure. The United States submitted a formal extradition request in December 2024, and Israeli authorities approved extradition. Charges against Gurevich include wire fraud, conspiracy, and money laundering, carrying potential sentences of up to 20 years for the most serious counts. TRM Labs, which assisted in blockchain tracing, confirmed his extradition to the United States in May 2025.","heading":"Criminal Investigation and Suspect Extradition","sources":[{"url":"https://www.trmlabs.com/resources/blog/key-suspect-in-190m-nomad-bridge-exploit-extradited-to-the-united-states","name":"trmlabs.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/israeli-authorities-arrest-nomad-bridge-hacker-approve-extradition-to-us/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/suspect-behind-190-million-nomad-bridge-hack-extradited-us","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The code vulnerability that enabled the exploit was introduced in a June 2022 upgrade — approximately six weeks before the August 1 exploit. The FTC's complaint alleged that Nomad failed to implement processes for receiving and addressing vulnerability reports and for responding to security incidents, and that it failed to adequately test the upgrade before deployment. Security analysts noted that a comprehensive audit of the upgrade, including review of the initialization parameters and their downstream effects on the verification logic, would likely have identified the zero-root misconfiguration. The Immunefi bug bounty platform, which published a post-mortem analysis, noted that the error was subtle in isolation but catastrophic in context — demonstrating the risk of incremental contract upgrades without holistic security review. Nomad had positioned itself as a security-first protocol and had attracted significant institutional backing in part on the basis of its claimed security posture.","heading":"Security Audit History and Pre-Exploit Context","sources":[{"url":"https://medium.com/immunefi/hack-analysis-nomad-bridge-august-2022-5aa63d53814a","name":"medium.com","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/analysis/nomad-loses-156-million-in-seventh-major-crypto-bridge-exploit-of-2022","name":"elliptic.co","type":"other","credibility":3},{"url":"https://cyberscoop.com/ftc-settles-with-illusory-systems-in-2022-cryptocurrency-hack/","name":"cyberscoop.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Nomad exploit occurred during a period of heightened bridge vulnerability across the DeFi ecosystem. Mandiant reported that nearly $2 billion was stolen from bridge protocols in 2022 alone, with Nomad accounting for a significant share. Other major 2022 bridge exploits included the Ronin Bridge ($625 million, attributed to North Korea's Lazarus Group), the Wormhole Bridge ($320 million), and the Horizon Bridge ($100 million). The Nomad attack was distinctive for its lack of technical barrier to participation: rather than a sophisticated state-sponsored actor deploying novel techniques, the exploit devolved into an open-access drain in which anyone monitoring the blockchain could participate by copying a transaction. Elliptic's analysis classified the event as the seventh major bridge exploit of 2022. The incident prompted broader industry discussion about the security risks inherent in cross-chain bridge architecture, the adequacy of upgrade testing procedures, and the need for circuit breakers or pause mechanisms that could limit damage once an exploit is detected.","heading":"Industry Context: Bridge Protocol Risk","sources":[{"url":"https://cloud.google.com/blog/topics/threat-intelligence/dissecting-nomad-bridge-hack","name":"cloud.google.com","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/analysis/nomad-loses-156-million-in-seventh-major-crypto-bridge-exploit-of-2022","name":"elliptic.co","type":"other","credibility":3},{"url":"https://edition.cnn.com/2022/08/03/tech/crypto-bridge-hack-nomad","name":"edition.cnn.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-11-10","event":"Illusory Systems Inc. incorporated in Delaware; Nomad Bridge protocol development begins under founders Pranay Mohan and James Prestwich.","source":""},{"date":"2022-04","event":"Illusory Systems raises $22.4 million in seed funding led by Polychain Capital, with participation from Circle Ventures, Hack VC, Archetype, Breyer Capital, and others.","source":"","date_original":"2022-04-01"},{"date":"2022-06","event":"A routine upgrade to the Nomad Replica.sol smart contract initializes the trusted Merkle root to 0x00, inadvertently making all message proofs automatically valid. The vulnerability goes undetected.","source":"","date_original":"2022-06-01"},{"date":"2022-08","event":"An initial attacker discovers the zero-root vulnerability and drains 100 WBTC. Within minutes, approximately 300 addresses begin copying the exploit transaction, substituting their own recipient addresses. Roughly $190 million is drained over approximately 150 minutes in what analysts describe as the first 'crowd-sourced' DeFi exploit.","source":"","date_original":"2022-08-01"},{"date":"2022-08-05","event":"Nomad announces a 10% bounty program, offering to refrain from legal action against exploiters who return 90% of stolen funds, plus a Whitehat NFT. CNBC and major outlets report on the offer.","source":""},{"date":"2022-08-09","event":"White-hat participants have returned approximately $32.6 million in tokens to Nomad's recovery address, representing early partial recovery.","source":""},{"date":"2023-02","event":"Class-action lawsuit Singh v. Illusory Systems Inc. filed in the U.S. District Court for the District of Delaware, alleging RICO violations including wire fraud and operating an unlicensed money-transmitting business.","source":"","date_original":"2023-02-01"},{"date":"2023-08","event":"FBI's San Francisco field office files an eight-count federal indictment in the Northern District of California against Alexander Gurevich, a Russian-Israeli dual national, alleging wire fraud, conspiracy, and money laundering in connection with the Nomad exploit.","source":"","date_original":"2023-08-01"},{"date":"2024-03-29","event":"U.S. District Court dismisses RICO claims in the Singh v. Illusory Systems class-action lawsuit.","source":""},{"date":"2024-12","event":"The United States formally submits an extradition request to Israel for Alexander Gurevich.","source":"","date_original":"2024-12-01"},{"date":"2025-04-19","event":"Alexander Gurevich re-enters Israel during Passover holiday and is summoned for an extradition hearing. He ignores the summons and legally changes his name to 'Alexander Block' in Israel's Population Registry.","source":""},{"date":"2025-05","event":"Gurevich applies for a new passport under his changed name and attempts to board a flight to Russia. Israeli police, coordinating with the DOJ, FBI, and Interpol, arrest him at the airport. Israeli authorities approve extradition to the United States.","source":"","date_original":"2025-05-01"},{"date":"2025-12-16","event":"The FTC announces a proposed settlement with Illusory Systems Inc. requiring the company to repay approximately $37.5 million to affected users, implement a comprehensive security program, and cease misrepresentations about product security.","source":""},{"date":"2025-12-19","event":"The proposed FTC consent order is published in the Federal Register for public comment, with a comment deadline of January 20, 2026.","source":""}],"sources_used":[{"url":"https://www.classaction.org/news/nomad-crypto-bridge-class-action-says-simple-programmer-mistake-allowed-186m-hack-in-2022","name":"classaction.org","type":"other","credibility":3},{"url":"https://www.crunchbase.com/organization/illusory-systems-inc","name":"crunchbase.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-nomad-hack-august-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/hack-analysis-nomad-bridge-august-2022-5aa63d53814a","name":"medium.com","type":"other","credibility":3},{"url":"https://nomoslabs.io/blog/nomad-bridge-exploit-technical-breakdown-190m-hack","name":"nomoslabs.io","type":"other","credibility":3},{"url":"https://cloud.google.com/blog/topics/threat-intelligence/dissecting-nomad-bridge-hack","name":"cloud.google.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/160851/nomads-190-million-bridge-exploit-drew-hacking-feeding-frenzy-of-300-addresses","name":"theblock.co","type":"other","credibility":3},{"url":"https://decrypt.co/106459/crypto-bridge-nomad-exploited-190m-frenzied-free-for-all","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/white-hat-hackers-have-returned-32-6m-worth-of-tokens-to-nomad-bridge","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.cnbc.com/2022/08/05/crypto-startup-nomad-offers-10percent-bounty-after-190-million-hack.html","name":"cnbc.com","type":"other","credibility":3},{"url":"https://www.theregister.com/2025/12/17/nomad_ftc_settlement/","name":"theregister.com","type":"other","credibility":3},{"url":"https://www.classaction.org/media/singh-v-illusory-systems-inc-et-al.pdf","name":"classaction.org","type":"other","credibility":3},{"url":"https://blockchain.bakermckenzie.com/2024/04/08/u-s-court-dismisses-rico-lawsuit-brought-in-connection-with-nomad-bridge-hack/","name":"blockchain.bakermckenzie.com","type":"other","credibility":3},{"url":"https://www.ftc.gov/news-events/news/press-releases/2025/12/ftc-will-require-illusory-systems-return-money-stolen-hackers-implement-information-security-program","name":"ftc.gov","type":"other","credibility":3},{"url":"https://www.federalregister.gov/documents/2025/12/19/2025-23407/illusory-systems-inc-analysis-of-proposed-consent-order-to-aid-public-comment","name":"federalregister.gov","type":"other","credibility":3},{"url":"https://www.trmlabs.com/resources/blog/key-suspect-in-190m-nomad-bridge-exploit-extradited-to-the-united-states","name":"trmlabs.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/israeli-authorities-arrest-nomad-bridge-hacker-approve-extradition-to-us/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/suspect-behind-190-million-nomad-bridge-hack-extradited-us","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/analysis/nomad-loses-156-million-in-seventh-major-crypto-bridge-exploit-of-2022","name":"elliptic.co","type":"other","credibility":3},{"url":"https://cyberscoop.com/ftc-settles-with-illusory-systems-in-2022-cryptocurrency-hack/","name":"cyberscoop.com","type":"other","credibility":3},{"url":"https://edition.cnn.com/2022/08/03/tech/crypto-bridge-hack-nomad","name":"edition.cnn.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:25:34.212817+00:00","updated_at":"2026-08-29T01:35:21.153+00:00"}}