Active exploitation of Nomad’s cross-chain token bridge began on August 1, 2022 at approximately 21:32 UTC, when four Ethereum transactions in block 15,259,101 removed a combined 400 wrapped bitcoin, or WBTC, from the bridge’s reserves.

The incident quickly expanded beyond those opening transactions. Nomad acknowledged through its Discord channel that it was aware of the activity and investigating, while contemporaneous reporting described WBTC, wrapped ether and later USD Coin leaving the bridge. The scale and identity of the participants remained uncertain during the first hours.

The development mattered because Nomad was infrastructure for moving representations of assets among otherwise separate blockchain environments. Users depended on its contracts to release tokens only after authenticating a corresponding cross-chain message. Once that authentication boundary failed, assets backing bridged tokens could be removed without legitimate deposits on another chain.

What the chain established

Later analysis by Coinbase’s blockchain security team placed the exploit window between August 1 at 21:32 UTC and August 2 at 05:49 UTC. It calculated that more than $186 million in ERC-20 tokens was taken during those eight hours and 17 minutes, primarily in USDC, WETH, WBTC and Covalent Query Token.

That figure describes Coinbase’s reconstruction of the complete incident, not the amount known to have left by the end of August 1 UTC. It also spans two calendar dates. Coinbase did not provide a complete token-by-token valuation table or a single disclosed price timestamp in the reviewed article, so the dollar total should be treated as an analytical estimate rather than a contemporaneous closing balance.

The opening block provides a cleaner event-date measurement. Coinbase identified four transactions using substantially identical exploit payloads with different recipient addresses, each removing 100 WBTC. Two were submitted privately through Flashbots and two appeared through the public mempool. The public exposure of reusable transaction data helped turn the incident from an initial compromise into a wider rush by additional addresses.

Contemporaneous coverage published at 23:05 UTC on August 1 correctly treated the situation as still developing. Its eventual estimate of as much as $190 million reflected information added after the drain continued into August 2. The available August 1 record therefore supports reporting the start of the exploit, but not presenting the final loss as if it were already settled at 21:32 UTC.

Why the failure was structurally important

A bridge concentrates risk differently from a conventional exchange account. It typically holds or controls assets on one network while contracts or applications recognize corresponding representations elsewhere. A defect in message verification can consequently place a large pool of unrelated users’ collateral behind one faulty security assumption.

Nomad’s monitoring design also proved relevant. Its later technical account said protocol watchers were intended to react to a compromised updater key. The August 1 transactions did not require a fraudulent updater signature, so that defense did not stop the contract-level failure.

The evidence available during the incident did not establish which addresses were malicious attackers, opportunistic participants or actors intending to return assets. Nor did it establish final recoveries or user losses. Those classifications depended on conduct after August 1 and should not be projected backward.

Later-confirmed technical context

On August 5, Nomad reported that an implementation error in its `Replica` contract allowed forged messages to pass authentication when they had not previously been processed. Fraudulent messages could then reach the `BridgeRouter`, which released tokens.

Nomad said the affected implementation had reached production on June 21 after an audit and that it subsequently unenrolled replicas and disabled the bridge interface. On August 17, the project described more than $186 million as affected and said more than 300 unique addresses had participated. Those details clarify the scale and mechanism, but they were not confirmed on August 1 itself.

The defensible event-date conclusion is narrower: a verifiable exploit of Nomad’s Ethereum bridge contracts began on August 1, exposed a reusable authentication failure and placed a substantial cross-chain reserve at risk before the final loss could be measured.

Primary sourceEtherscan — Initial Nomad exploit transaction in Ethereum block 15,259,101

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.