A faulty initialization of Nomad bridge's message verification made arbitrary withdrawals possible, and a crowd of copycats drained roughly $190M. A portion was later returned by white-hat actors.
No verified attacker addresses are listed for this incident. We only publish addresses confirmed against an authoritative source.
Figures are approximate, compiled from public reporting. Attacker addresses are included only where verified against an authoritative source. Attribution (e.g. Lazarus Group) is shown only when publicly stated by an official body.
© 2026 ChainAnalyzer. All rights reserved.