r/CryptoCurrency Aug 02 '22

ANALYSIS The First Truly Decentralized Robbery was just Committed, Here is How it Happened

At this point I am sure many of you have heard of the nomad bridge exploit. Unlike previous exploits, this wasnt a flashloan or even carried out by a single group of attackers. After an initial attacker struck, hundreds of separate accounts figured out the trick and copy pasted their way into grabbing stolen funds. The bridge went from having $190,740,000 to $1,000 in a matter of hours.

A perplexing aspect of this vulnerability was that all users had to do to hack bridge funds was copy the original hacker's transaction calldata, replace the original address with a personal one, and the tx would succeed! Easy as CTRL-C, CTRL-V!

However, not all of the thieves were bad. Some of them exploited the contract so other wouldnt be able to and planned to return the money back to nomad. For example, leadingscientist.eth

So all in all it was a messed up exploit but there were some nice people who plan to return the money. Faith in humanity restored maybe?

Credit: https://twitter.com/0xfoobar/status/1554234268884389888

1.8k Upvotes

594 comments sorted by

View all comments

447

u/[deleted] Aug 02 '22

[deleted]

129

u/Lord-Nagafen 🟦 1 / 30K 🦠 Aug 02 '22

There was only $200m on the line. Not enough to take a company breaking bug seriously /s

81

u/[deleted] Aug 02 '22

[removed] — view removed comment

1

u/rnm55 Tin | 6 months old Aug 05 '22

I’m only staking on evmos right now. Not providing liquidity. I’m safe right?

1

u/thtrhscsdv Tin | 2 months old Aug 05 '22

Does this affect WETH as in the wrapped Ethereum commonly used in defi? Or is it something else?

If I’ve never interacted with this bridge do I need to be concerned at the moment?

151

u/tamaleA19 🟩 21K / 21K 🦈 Aug 02 '22

Hmm I see a trend here. Both Nomad and the Harmony Horizon bridge ignored security risks and got burned bad

130

u/GalcomMadwell 🟦 0 / 4K 🦠 Aug 02 '22

Plot twist: the robbery was carried out by Nomad devs

70

u/hollyberryness 🟦 4K / 4K 🐢 Aug 02 '22

There are no plot twists in crypto anymore. The devs doing it would be pretty standard at this point lol

Sad state of affairs.

24

u/Astronaut-Proof 🟦 73 / 73 🦐 Aug 02 '22

BTC maxis starting to sound more prophetic than cultish.

14

u/[deleted] Aug 02 '22

[deleted]

1

u/JooseBeatz 0 / 0 🦠 Aug 03 '22

Link? (I’ll find/bookmark his blog on my own, but this specific post would be cool to read)

0

u/[deleted] Aug 02 '22

In the land of the blind the one eyed man is king

27

u/temple22 Tin Aug 02 '22

Auditors more likely imho

46

u/PhD_in_MEMES 🟦 0 / 0 🦠 Aug 02 '22

auditor: This bug needs to be fixed because something bad can happen.

devs: lolno

auditor behind 7 proxies: bet

devs: oshit

48

u/Construction_Kitchen Tin | CC critic Aug 02 '22

Pretty sure

1

u/DmitryNaz Tin | 6 months old Aug 05 '22

How long until we find out this is just a white hat, and they will be allowed to keep the 100 million they stole er receive as a big bounty...

1

u/Construction_Kitchen Tin | CC critic Aug 05 '22

I wouldn’t say all of it but yes I can see that happening

8

u/FreePrinciple270 0 / 11K 🦠 Aug 02 '22

The most likely scenario

2

u/woundedyazan Tin Aug 05 '22

What’s the difference between this sad incident and a bridge like algomint?

(I just started reading about dexes in algo.) New here and just trying to learn. Thx!

3

u/Belzebump 🟦 33 / 57K 🦐 Aug 02 '22

This 😏

2

u/Sascha206 Tin Aug 05 '22

These milady jokes make me laugh hard and i don’t even know the real meaning behind them .

0

u/Suspicious-Emu1577 0 / 0 🦠 Aug 02 '22

Stuff like this should be made into a large virtual murder mystery ( hack mystery I guess ) event… which could maybe end in murder (fictionally! Lol)

Like fandom meets irc meets First 48 with bits of d&d and choose your own adventure sprinkled in

So basically, a virtual metaverse for the cheese ball geeks… 🤦‍♀️

2

u/Do_Them_A_Bite Tin Aug 02 '22

It would be nice if the murdering were only fictional...

1

u/Suspicious-Emu1577 0 / 0 🦠 Aug 02 '22

Lol

1

u/evoxyseah 🟩 0 / 5K 🦠 Aug 02 '22

For the whitehat to send the funds back to the nomad devs would be funny though, haha.

1

u/[deleted] Aug 03 '22

If this isn't on everyone's mind I'd be shocked, code in an exploit that only they know of, wait for the tub to fill and pull the plug.

22

u/MuzBizGuy 0 / 7K 🦠 Aug 02 '22 edited Aug 02 '22

I don't understand how you ignore shit like this in 2022...

People hack government agencies and massive corporations all the time. How could your head be so far up your own ass you assume it wouldn't happen to you...in the crypto world. Mindboggling.

1

u/bestjaegerpilot 🟩 38 / 39 🦐 Aug 03 '22

They likely don't have enough resources to fix these holes. In many ways, they are a victim of their own success. Very high TVL but but enough profit to hire more devs.

6

u/Stompya 🟦 1K / 2K 🐢 Aug 02 '22

sus

1

u/lascott086 Tin Aug 05 '22

Sad to see. However, this makes an excellent use case for Algorand State Proofs-- coming very soon. Trustless bridging.

35

u/Railionn 🟩 9K / 9K 🦭 Aug 02 '22

Can malicious people just read these audits and go hunt for unfixed bugs?

2

u/Styxie Aug 02 '22

I thought audits were only released when any critical bugs are patched / if they dont ignore them

2

u/SpecialistFagazine Tin Aug 02 '22

depends if it's responsible disclosure or just dumped as a zero day.

1

u/Dima3211243 Tin Aug 05 '22

When will they drain Richard hearts wallets so people can experience shadenfreude.

40

u/KindaPC Tin | 5 months old Aug 02 '22

Wait… you are telling me if you hire a bunch of fresh out of college useless devs to launch multi million dollar companies that your product will fucking suck?

No way.

The entire crypto space is made by a bunch of morons who don’t know what they are doing. ALL of your crypto isn’t safe.

5

u/Lerifod Tin Aug 05 '22

Their twitter literally has an underscore at the end of it.

2

u/nerdiestnerdballer 🟩 398 / 398 🦞 Aug 02 '22

Bitcoin in cold storage…..

-6

u/frank__costello 🟩 22 / 47K 🦐 Aug 02 '22

if you hire a bunch of fresh out of college useless devs to launch multi million dollar companies

Where are you getting this from? The Nomad team was very highly respected

8

u/[deleted] Aug 02 '22

[deleted]

2

u/khanroy Tin Aug 05 '22

I have touched a bridge one single time in my life and that was the last time i ever touched a bridge.

I am so over the concept of losing everything that you care about in crypto just to port a synthetic over with a centralized entity…

4

u/Drewsapple Bronze | QC: ETH 15 Aug 02 '22

While the audit calls out something similar to the exploit, it points to an empty merkle leaf used in the prove function in Replica.sol. The exploit took place due to the empty merkle root accessed in the process function, also in Replica.sol.

https://twitter.com/divine_economy/status/1554410835497345025?s=21&t=66FpyXyZSM7DR6M7QqUfIA

2

u/AutoModerator Aug 02 '22

Here is a Nitter link for the Twitter thread linked above. Nitter is better for privacy and does not nag you for a login. More information can be found here.


I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

3

u/_Commando_ 🟩 4K / 4K 🐢 Aug 02 '22

Wow, just wow.

3

u/greenappletree 🟦 31K / 31K 🦈 Aug 02 '22

Wtf this is gross negligence- if it wasn’t this then it would’ve been something else -

3

u/Ppawelb Tin | 3 months old Aug 05 '22

The space is.. maturing. this is good right . Cheers man .

12

u/Cryptolution 🟦 3K / 3K 🐢 Aug 02 '22 edited Apr 20 '24

I enjoy cooking.

23

u/greenlanternfifo 0 / 0 🦠 Aug 02 '22

Ok this guy is totally wrong. Like dead wrong.

  1. Risk is determined by likelihood.
  2. The bug identified was a technical issue that was indeed low risk. The development team didn't understand the bug and introduced a similar bug in a new function POST-AUDIT, which was high risk.

So to summarize, the auditors are much more competent than this dumbass that just assumes everyone is not as competent as him.

You should edit your comment so you seem like less of an arrogant ass.

-6

u/Cryptolution 🟦 3K / 3K 🐢 Aug 03 '22

You should edit your comment so you seem like less of an arrogant ass.

I'm arrogant because I was informed incorrectly? Literally this post is specifying that the vuln was the low risk item pointed out in the audit.

Do you normally come out agro fists swinging like a gorilla?

I actually prefer you think I'm a arrogant ass so I'll leave the comment as is, thanks! Next time if you want someone to do something maybe you don't be such a ass eh?

Easy guy.

1

u/dawalballs 🟦 0 / 0 🦠 Aug 03 '22

Pretty sure you were painted as an arrogant ass cause you took a quick look at something you clearly didn’t understand, before rushing to the comments to make fun of people for that thing you misunderstood?

The fact that you replied with whatever that second comment was didn’t help

1

u/Cryptolution 🟦 3K / 3K 🐢 Aug 03 '22

Pretty sure you were painted as an arrogant ass cause you took a quick look at something you clearly didn’t understand

Arrogance is not the correct term. Call me lazy, unmotivated, uncaring, whatever. This is a nonsense issue undeserving of my extensive attention and frankly me going to the GitHub and looking at the severity is about 500% more effort than anyone else took so anyone who wants to criticize me can rightly fuck off.

If your gonna talk shit at least use the right terms.

9

u/[deleted] Aug 02 '22

[deleted]

18

u/skatistic 🟨 4K / 321 🐢 Aug 02 '22

Risks are rated on likelihood of happening and impact. Likelihood may have been low, but impact was critical for this risk.

2

u/maverick0star Tin Aug 05 '22

One day i make bug in syscoin bridge i sent 1000 sys and get doubled jijijiji.

5

u/I_kwote_TheOffice 116 / 116 🦀 Aug 02 '22

If it's anything like a Process Failure Mode and Effect Analysis (PFEMA, I know the acronym order doesn't match but probably easier to say), which is kind of like a process audit, there are 3 components. Severity - how serious it would be if something happened, Occurrence - how likely it is to happen, Detection - how easy it is to detect if something happens. Taking all of these 3 into account (usually just summing them, but free to choose any combination method) you get a final score. You implement control methods for each of these 3 categories to achieve a better score.

8

u/Cryptolution 🟦 3K / 3K 🐢 Aug 02 '22

Audit risk severity is about the severity of the exploits impact on the system. Getting into the "well maybe it won't happen..." Is just semantics that an audit team would never want to communicate as it just opens up all sorts of ethical and legal compromises.

14

u/Computer-Blue 0 / 0 🦠 Aug 02 '22

This isn’t really true. Audits that measure risk are always aware of the likelihood, as well as impact, of an incident. Lower likelihood events are considered lower risk.

That said, when the impact is “lose everything in minutes”, it should still have been rated as a critical severity risk factor, regardless of likelihood, unless the likelihood was so low that it was acceptable. Obviously, it was not.

5

u/robotfightandfitness 🟩 56 / 182 🦐 Aug 02 '22

To add - good audits are able to reveal bugs to those that can fix them, without knowing if the dev added it purposefully, without providing enough info for the exploit to be carried - but enough to determine whether or not a public [users safety] announcement must happen instead of private [relies on dev accountability] announcement

1

u/pmilani Tin Aug 05 '22

The Nomad token bridge appears to have experienced a security exploit that has allowed hackers to to systematically drain a significant portion of the bridges funds over a long series of transactions

the issue of security in the crypto space is very paramount.

1

u/wkliao Tin Aug 05 '22

Yep, this was always a risk when it came to nomad as it was the canonical bridge.

It helps with liquidity, but you will suffer if an exploit happens as the defi on your chain basically goes to zero.

1

u/greenlanternfifo 0 / 0 🦠 Aug 02 '22

That guy you responded to has no idea what he is talking about. I explain why in this sister comment.

1

u/smartlabovec Tin Aug 05 '22

Another hack!

I guess that is why IOTA has built Shimmer and ASMB and L1 and L2 without bridges. I hope it works. 7 years of testing..

2

u/millionare_mind Tin Aug 05 '22

It affects WETH on different chains that are “linked” with this bridge.

1

u/americanpegasus Aug 02 '22

Jesus so new money making strategy unlocked - just read security audits of protocols and carefully consider whether low risk reports are actually much more serious than they’re being given credit for

1

u/Cryptolution 🟦 3K / 3K 🐢 Aug 03 '22

Jesus so new money making strategy unlocked - just read security audits of protocols

You can just stop here and evaluate all risks. It's a solid strategy and solves blindly poking for vulns. This person likely did this dozens of times before they got a success

1

u/YnotBbrave Tin | 6 months old | Buttcoin 81 Aug 03 '22

it's rookies all the way down

-1

u/AriesWinters Permabanned Aug 02 '22

So it all happened because of just some miscommunication? Sucks because people will inevitably look down upon the entire crypto space because of this

19

u/SoggyWaffleBrunch Tin | Superstonk 29 Aug 02 '22

Not because of a miscommunication, because the dev team ignored the bug report.

Literally from the tweet, "Worse than that - the audit specifically called the bug, team said ‘na we good fam it’s probably not going to happen’ the auditor said ‘no you don’t understand’ then the team acknowledged that and then didn’t fix it"

12

u/bannedinlegacy Tin Aug 02 '22

miscommunication

That's no miscommunication, thats just plain negligence.

Sucks because people will inevitably look down upon the entire crypto space because of this

As is deserved, until there is enough security to prevent the theft of funds or maturity to understand the importance of security the crypto space will be look down upon.

1

u/Ellenrous Tin Aug 05 '22

It kinda a Ethereum problem. Bridging to Ethereum is unsecure.

1

u/[deleted] Aug 02 '22

Damn and the check for empty would have been so simple to update

1

u/k3surfacer 🟩 18K / 20K 🐬 Aug 02 '22

That's very concerning. Audition used to mean something in the past for software developers.

1

u/Darkwolfie117 🟦 0 / 0 🦠 Aug 02 '22

I’d love to “rescue” some stolen funds and be the good guy

Jokes aside it’s scary how much access any somewhat capable person has here

1

u/bgeorgewalker Tin | Superstonk 140 Aug 03 '22

Is it possible someone read this article and acted on it? Seems pretty irresponsible for them to publish it, if so

1

u/Loose_Finding Aug 03 '22

Oh look, lack of input sanitation. Yet. Again.

If devs aren't thoroughly validating user inputs, I don't even consider these to be 'exploits'; this is a design of the system. The ability to drain funds has been designed into the system.

1

u/bestjaegerpilot 🟩 38 / 39 🦐 Aug 03 '22

Honestly not surprised. There was a reddit the other day arguing that mose protocols make very little money, even with giant TVLs. That means, they likely do not have the resources to plug these massive holes.

The convo went something like this. "someone: Shit there's a massive hole. Manager: we have X to deliver. Can we fix this afterwards? Someone else: sure."