security-incident · Nomic · nBTC · Osmosis · security
Nomic Forwarding Bug Created Unbacked nBTC on Osmosis
SlowMist attributes the incident to a custom-forwarding flaw; response figures and recovery plans remain attributed while the final economic loss is unresolved.

Blockchain security firm SlowMist says an attacker exploited a bug in Nomic's custom-forwarding process to create unbacked nBTC vouchers and send them to Osmosis.
The account distinguishes the affected bridge logic from the surrounding networks: SlowMist says Osmosis and the Inter-Blockchain Communication protocol were not themselves compromised.
According to the same incident record, the event left 39.84 nBTC of minted supply in an Alloyed BTC pool and reduced its backing. Osmosis responded by freezing Nomic and Alloyed BTC flows and coordinating a validator upgrade. SlowMist also reported that 22.65 BTC associated with the attacker was frozen.
Those quantities, the proposed seizure and any plan to cover a remainder are attributed incident-response claims, not a final accounting. The recovered amount, residual liability and ultimate economic loss may change as governance and remediation proceed.
The durable lesson is architectural: an application-specific forwarding layer can create systemic collateral risk even when the base networks and interoperability protocol continue operating as designed.
Sources and disclosures
Primary incident record: SlowMist Hacked archive. Mechanism, response and asset figures are attributed to SlowMist and the accounts it links.
Update note
Observed September 9, 2026 BRT. Final loss and recovery outcomes remain developing.
