Original source text
Osmosis, the prominent decentralized exchange in the Cosmos ecosystem, suspended key operations for its synthetic Bitcoin asset on September 9 after an exploit on the Nomic blockchain allowed an attacker to double-spend nBTC. The exchange froze minting, redemption, deposits, and withdrawals for alloyed BTC (allBTC) while moving to contain the damage.An emergency upgrade managed to lock 22.65 BTC in the attacker’s address before the funds could be moved. Approximately 39.84 nBTC were compromised in the incident, meaning more than a third of the asset backing that allBTC holders were counting on was suddenly in question.
What happened and how much is at stake The exploit targeted a flaw in a custom forwarding mechanism on the Nomic chain, a Cosmos-based blockchain designed to bring Bitcoin into the broader interchain ecosystem. That flaw allowed false vouchers to be created through a double-spend of nBTC, which is essentially a wrapped representation of Bitcoin living on Nomic.
Those fraudulent vouchers then made their way to Osmosis via the Inter-Blockchain Communication (IBC) protocol. The IBC protocol itself wasn’t compromised, and Osmosis’s own systems weren’t breached directly. The vulnerability lived upstream, on Nomic’s side.
The 39.84 nBTC affected represents roughly 36% of alloyed BTC’s total backing on Osmosis. That figure accounts for approximately 30% of the total BTC exposure across the entire exchange.
Osmosis moved quickly after detecting the issue. The team paused all inflows and outflows related to allBTC and pushed through an emergency chain upgrade. That upgrade successfully froze 22.65 BTC sitting in an address linked to the attacker, preventing further extraction of the stolen funds.
Trading of BTC in existing liquidity pools has continued despite the freeze. But the suspension of minting and redemptions effectively means no one can create new allBTC or cash out existing holdings until the situation is resolved.
The recovery plan Osmosis has outlined a two-pronged approach to making affected users whole. First, the team plans to propose a governance vote to seize the 22.65 BTC currently frozen in the attacker’s address. In the Cosmos ecosystem, governance proposals can authorize on-chain actions if enough token holders vote in favor, giving the community direct say over how stolen funds are handled.
Second, Osmosis intends to tap the community pool to cover the gap between the frozen BTC and the total amount compromised. The goal is to restore the 1:1 backing of alloyed BTC, ensuring that every synthetic Bitcoin token on the platform is fully collateralized again.
A full incident report and detailed recovery plan are expected in the coming days. The timeline for restoring normal operations, including minting and redemptions, hasn’t been specified yet.
Why cross-chain bridges keep breaking The exploit targeted Nomic’s custom forwarding mechanism, exactly the type of bespoke infrastructure that tends to harbor undiscovered vulnerabilities. The IBC protocol itself can be battle-tested over time, but the custom pieces bolted onto it often haven’t faced the same scrutiny.
Alloyed BTC on Osmosis is designed to function as a unified Bitcoin asset that aggregates multiple bridged versions of BTC into a single tradeable token. But that design also means a vulnerability in any single backing asset, like nBTC from Nomic, can compromise the integrity of the whole product. In this case, nBTC represented a large enough share of allBTC’s backing that a single exploit threatened more than a third of the asset’s collateral.
What to watch from here The immediate question is whether the governance proposal to seize the frozen BTC will pass and how quickly the community pool can cover the remaining shortfall. For Osmosis users holding allBTC, minting and redemption remain frozen, and full restoration depends on governance action and community pool funding. Trading that continues in liquidity pools provides some liquidity outlet, but it is not the same as being able to freely redeem the underlying asset.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.