Key Takeaways
- Nomic’s June 25 bug minted 39.84 unbacked nBTC, blowing a 36% hole in Alloyed BTC’s backing.
- Osmosis locked down 22.65 BTC after the Nomic mess sat unnoticed for a wild 74 days.
- Osmosis now wants governance to grab 22.65 BTC and get Alloyed BTC fully backed again.
Nomic Bug Leaves Alloyed BTC With a 36% Backing Hole
According to the decentralized exchange (DEX) platform Osmosis, a software flaw in Nomic’s custom IBC forwarding path allowed an attacker to mint unbacked nBTC and stash most of it inside Osmosis’s Alloyed BTC basket. What sounds almost unbelievable, yet is demonstrably true, is that the mint occurred on June 25 and remained hidden in plain sight for 74 days.

“Recently, we became aware of an exploit on the Nomic chain. The exploit allowed the attacker to double-spend nBTC, allowing them to send false vouchers to Osmosis. Osmosis and IBC were not compromised, as the bug was in a custom forwarding mechanism on Nomic. 39.84 nBTC of the minted total sits within Alloyed BTC, representing ~36% of its backing,” Osmosis disclosed this week.
Osmosis Freezes Funds and Turns to Governance for a Fix
Once the problem was discovered, Osmosis explained on X that it quickly shut down deposits and withdrawals involving Nomic and Alloyed BTC to stop any more funds from moving. The team then worked with validators on an emergency update that locked 22.65 BTC sitting in the attacker’s wallet.
“We will propose seizing these assets to governance and ask governance to use accrued BTC in the community pool to cover the remaining balance and restore the full backing of Alloyed BTC,” the team wrote.
Independent Researcher Finds the Bug That Minted Alloyed Bitcoin Twice
The independent researcher known as Rarma dug into the code and shared insights on what went wrong on X. In simple terms, Nomic’s system accidentally created the same bitcoin deposit twice. The first batch was handled normally, but the second became extra nBTC that could actually be spent, the researcher’s X post noted. Rarma found that this was the only one of 18 similar processes in the file that created the coins twice, and the system did not even verify who controlled the account receiving them.
Pulling it off cost just one satoshi, an extremely cheap attack, and Rarma wrote at the time that the faulty code was still sitting unchanged in Nomic’s development branch when he published his findings on Sept. 8. The Osmosis security update was posted to X the very next day.
Despite the BTC backing problem the team is dealing with, the incident still offers a useful reminder about so-called BTC tokens minted on other chains, as their backing is only as reliable as the custom code responsible for minting the claim.







