Nomad Bridge Replay Exploit, August 2022: What Happened & What to Check
A routine upgrade left Nomad accepting any message as proven. Hundreds of addresses copied the same transaction and drained the bridge in…
Searches every incident record, jurisdiction page, glossary term and guide.
A routine upgrade left Nomad accepting any message as proven. Hundreds of addresses copied the same transaction and drained the bridge in…
Compromise of two of five multi-signature keys was enough to authorise withdrawals from Harmony's Horizon bridge, taking roughly $100m.
An attacker borrowed enough voting power in a single transaction to pass their own malicious proposal and drain roughly $182m.
Attackers obtained enough Ronin validator signatures to forge withdrawals, draining 173,600 ETH and 25.5m USDC. The theft went unnoticed for six days.
A flaw in Wormhole's Solana signature verification let an attacker mint 120,000 wETH without depositing collateral. Jump Crypto replaced the shortfall.
A compromised Cloudflare API key let attackers inject approval-harvesting script into the BadgerDAO front end. The contracts were never touched.
Manipulation of the price feed used to value collateral let an attacker borrow far beyond its worth, taking roughly $130m.
An attacker exploited Poly Network's cross-chain contract to reassign the keeper role, taking roughly $611m — then returned substantially all of it.
Roughly $281m left KuCoin hot wallets. A large share was recovered through token contract upgrades and freezes by issuers.
A reentrancy flaw in The DAO's split function drained roughly 3.6 million ETH and led to the contentious hard fork that produced…