Double-Spend Exploit on Nomic Chain Forces Osmosis to Freeze Bitcoin Operations
Osmosis, a decentralized exchange in the Cosmos ecosystem, suspended minting, redemption, deposits and withdrawals for its synthetic Bitcoin asset (allBTC) on September 9 after attackers exploited a flaw on the Nomic blockchain. The bug in a custom forwarding mechanism allowed false vouchers to be created through a double-spend of nBTC, a wrapped Bitcoin representation used on Nomic. These fraudulent vouchers then flowed into Osmosis via the Inter-Blockchain Communication (IBC) protocol, which itself was not compromised.
About 39.84 nBTC were affected, representing roughly 36% of allBTC's backing on Osmosis and around 30% of the exchange's total Bitcoin exposure. Osmosis responded with an emergency chain upgrade that froze 22.65 BTC in the attacker's address before it could be moved further, though trading within existing liquidity pools has continued.
The incident highlights how vulnerabilities in one blockchain can ripple into connected ecosystems even when a platform's own systems remain secure. Osmosis's own infrastructure was not directly breached; the root cause lay upstream in Nomic's design.