Glass Ledger
How the Nomic Exploit Drained Osmosis's Bitcoin
A double-spend bug on the Nomic chain forged Bitcoin backing for Osmosis's allBTC token. Here is exactly how the exploit worked, step by step.
On September 9, 2026, Osmosis, the largest decentralized exchange in the Cosmos ecosystem, froze minting, redemption, deposits, and withdrawals for its Alloyed BTC token, known as allBTC. The cause was a double-spend bug on Nomic, a separate Cosmos-based chain that Osmosis relies on to bring Bitcoin into its system as nBTC, a token meant to represent real bitcoin held one-to-one. The Nomic exploit ended up compromising roughly 36% of allBTC's entire backing. Understanding how it actually happened, step by step, matters more than the headline number, because the mechanism is the part that tells you what to check the next time you are asked to trust a token that claims to represent bitcoin you never actually hold.
Step 1: What Nomic Was Supposed to Guarantee
Nomic is built to let bitcoin move into the wider Cosmos interchain ecosystem. A user sends real BTC to Nomic's system, Nomic verifies that deposit against Bitcoin's own proof-of-work by checking block headers, and in exchange mints nBTC, a Cosmos-native token that is supposed to always be redeemable one-to-one for the underlying bitcoin. That nBTC can then move over the Inter-Blockchain Communication protocol, IBC, to other Cosmos chains, including Osmosis, where it becomes part of the collateral basket backing allBTC. The entire model depends on one guarantee holding at all times: one unit of nBTC always corresponds to exactly one unit of real, deposited bitcoin, never more.
Step 2: The Bug in Nomic's Forwarding Mechanism
The flaw sat in a custom forwarding mechanism on Nomic's side, not in IBC itself and not in Osmosis's own contracts. That mechanism handles how a Bitcoin deposit gets translated into an nBTC minting instruction as it moves toward the interchain. A flaw in that translation step allowed the same underlying bitcoin value to support more than one nBTC claim at once, a textbook double-spend, but happening inside the bridge logic rather than on Bitcoin's own ledger. Bitcoin's base chain was never at risk at any point in this incident.
Step 3: How the Double-Spend Actually Reached Osmosis
Once the bug let forged nBTC vouchers exist, those vouchers moved through IBC to Osmosis exactly like legitimate ones, because IBC's job is to faithfully relay a message from one chain to another, not to independently re-verify that the sending chain's internal accounting was honest. Osmosis received what looked like properly minted nBTC and folded it into allBTC's backing pool the same way it always does. By the time anyone caught the discrepancy, approximately 39.84 nBTC's worth of the token had been created without real bitcoin standing behind it, about 36% of allBTC's total backing at that point.
Step 4: What Osmosis Did Once the Exploit Was Caught
Osmosis's response had two parts. First, it froze the affected functions outright: no new allBTC could be minted, no existing allBTC could be redeemed, and no deposits or withdrawals could move, stopping the damage from spreading to anyone holding or trading the token while the backing gap remained open. Second, an emergency upgrade managed to lock 22.65 of the compromised BTC-equivalent in the attacker's own address before it could be moved further, recovering the majority of the exposure before it left the system entirely.
Step 5: What Happens Next
Osmosis has said it will bring a governance proposal to OSMO holders asking them to formally seize that frozen 22.65 BTC. Recovering that amount still leaves a gap, roughly 17.19 BTC (39.84 minus the 22.65 already locked), between what was compromised and what is recoverable from the attacker directly. To close that remaining gap and restore a genuine one-to-one backing ratio, Osmosis intends to ask the same governance process to authorize using bitcoin already sitting in the protocol's own community pool to recapitalize allBTC. Both proposals still have to pass a vote before any of this is final, and allBTC stays frozen until they do.
The Steps, Recapped, and What to Check First
Read back through those five steps and the pattern is specific, not generic: a bridge's own internal forwarding logic broke, forged claims moved through infrastructure designed to relay messages faithfully rather than audit them, and a token marketed as fully backed ended up more than a third unbacked before anyone caught it. Before trusting any token that claims to represent bitcoin you do not directly hold, the one thing worth checking first is exactly this: does the system that mints the token verify each new unit against a fresh, independently checkable proof that real bitcoin actually moved, every single time, or does it trust an upstream chain's own internal bookkeeping the way Osmosis trusted Nomic's.
NexusPool does not touch this kind of bridging risk at all, because it does not issue a token that stands in for bitcoin. A block a NexusPool miner finds pays out through a coinbase transaction that sends the reward, subsidy plus fees, directly to the miner's own address, with 0% pool fee, across Bitcoin, Litecoin, Dogecoin, and Bitcoin Cash. The signed, offline-checkable receipts behind that design are documented on NexusPool's Glass Ledger page, and the protocol support behind it, including native Stratum V1 and Stratum V2, is covered on NexusPool's technology page. Anyone who wants to see how a payout is checked before a block is even found can review NexusPool's Payout Preflight tool. None of this is a claim that any bridge or wrapped-asset system, including Nomic or Osmosis specifically, is unsafe going forward, and it is not a claim about the odds of finding a block, which are set entirely by network difficulty relative to a miner's own hashrate and identical for every miner on a given chain regardless of what happens on any bridge. It is not investment advice, and it is not a claim that NexusPool's own core software is open source or public today. For a detailed account of how the exploit and Osmosis's response actually unfolded, see CryptoBriefing's reporting on the Nomic exploit.
Trust nothing. Verify how a token that claims to represent bitcoin actually checks each new unit before you treat its backing as settled fact.