Osmosis's Alloyed BTC fund lost 36 percent of its backing after an attacker exploited a software flaw on the Nomic chain to mint unbacked nBTC. The exploit went undetected for 74 days—from June 25 through early September.
The attacker minted 39.84 unbacked nBTC, representing approximately 36 percent of the fund's total backing, according to Osmosis's disclosure this week. The vulnerability sat in Nomic's custom IBC forwarding mechanism, which failed to verify account ownership when processing bitcoin deposits. The attacker exploited this gap to double-spend nBTC and send false vouchers to Osmosis. The actual attack cost only one satoshi.
Osmosis confirmed that its own platform and the IBC protocol itself remained uncompromised. Independent researcher Rarma analyzed the code and determined that Nomic's system created the same bitcoin deposit twice within one of 18 similar processes in the relevant file.
Upon discovery, Osmosis immediately suspended all deposits and withdrawals involving Nomic and Alloyed BTC. The team then coordinated with validators to deploy an emergency update that locked 22.65 BTC in the attacker's wallet.
Osmosis plans to propose seizure of the locked assets through governance and will request approval to use accrued BTC from the community pool to cover the remaining shortfall. The goal is full restoration of Alloyed BTC backing. The incident demonstrates that wrapped bitcoin tokens on other chains are only as secure as the custom minting code that underpins them.