Osmosis Freezes $1.79M After nBTC Exploit
Osmosis froze 22.65 BTC worth about $1.79 million after a Nomic nBTC double-spend exploit affected 39.84 nBTC, causing a $3.15 million backing shortfall.
Bitcoin-related inflows and outflows have been suspended by Osmosis due to a Nomic chain issue that allowed an attacker to transfer fake vouchers to Osmosis and double-spend nBTC. 39.84 nBTC, or almost 36% of the backing of Alloyed BTC, were impacted by the incident. Osmosis said that neither IBC nor its own chain had been hacked. Since then, 22.65 BTC linked to the attacker have been frozen by an emergency update, and the protocol intends to request governance approval in order to seize those assets and restore full backing.
Nomic Chain Exploit Allowed nBTC Double-Spend
The problem started on the Nomic chain, where a hacker took advantage of a flaw that made it possible to double-spend nBTC. The resultant fake vouchers were subsequently used by the attacker to transfer assets to Osmosis.
The distinction is crucial since, according to Osmosis, neither the Osmosis chain nor IBC were compromised by the exploit. Rather, the Nomic chain's handling of nBTC and its representation prior to those assets reaching Osmosis was the source of the issue.
Nevertheless, because the impacted nBTC was one of the assets supporting the BTC-linked product, the issue posed a serious threat to Osmosis' Alloyed BTC system.
39.84 nBTC Represents 36% of Alloyed BTC Backing
Osmosis reports that the exploit affects 39.84 nBTC. That sum amounts to about 36% of Alloyed BTC backing, so the incident is significant enough to have an immediate impact on the asset's backing ratio.
The Bitcoin representation issued by Nomic that is utilised in the Osmosis ecosystem is the impacted nBTC. A portion of Alloyed BTC's backing was revealed as a result of the incident since the exploit produced nBTC that was incorrectly backed.
In response, Osmosis stopped both inflows and outflows. While the team limits the exploit and works through the recovery process, the action is meant to stop the impacted assets from moving further.
While the protocol assesses the precise impact and subsequent actions, the pause also restricts the ability of users or attackers to relocate impacted assets.
Recently, we became aware of an exploit on the Nomic chain. The exploit allowed the attacker to double-spend nBTC, allowing them to send false vouchers to Osmosis. Osmosis and IBC were not compromised, as the bug was in a custom forwarding mechanism on Nomic.
— Osmosis 🧪 (@osmosis) September 9, 2026
39.84 nBTC of the…
Emergency Upgrade Freezes 22.65 BTC
Osmosis has already directly challenged the position of the attacker. While the recovery procedure is ongoing, an emergency update froze 22.65 BTC in the attacker's address, making it impossible to transfer those funds.
Because it gives Osmosis some of the resources required to fill the backing gap caused by the vulnerability, the frozen Bitcoin is very significant.
Freezing the assets does not, however, instantly restore them to the protocol. To acquire the frozen Bitcoin, Osmosis intends to get governance approval. Therefore, before those funds can be formally reclaimed and used to resolve the impacted backing, the community must approve the proposed action.
Osmosis Plans to Restore Full Backing
Beyond the blocked cash, Osmosis has a recovery plan. Additionally, the protocol intends to fully back Alloyed BTC by using BTC from the community pool.
Thus, the strategy consists of two steps, i.e., first, get governance clearance to retrieve the 22.65 BTC that was frozen in the attacker's address, and second, use BTC that is stored in the community pool to meet the remaining backing need.
Osmosis has stopped nBTC-related inflows and withdrawals because containing the exploit continues to be the top priority. Restoring Alloyed Bitcoin's support after 39.84 nBTC were impacted is the longer-term goal.
For Osmosis users, the key issue now is whether governance approves the proposed seizure and community-pool allocation, allowing the protocol to close the backing gap created by the Nomic chain exploit.
If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- $90K Crypto Loss After Chrome Extension Hack
- Liquid Network Loses $320M in Security Breach
- AMC CEO Blasts Robinhood Over Unregistered Stock Tokens
- Coinbase Launches Bitcoin-Backed Mortgages
- ECB Pushes Central Bank Money On-Chain
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.