According to Protos, an attacker minted more than 40 BTC worth of Nomic’s nBTC out of thin air on June 25, and Osmosis did not detect it for 74 days. Later disclosures showed that 36% of allBTC on Osmosis had no backing.

During that 74-day stretch, neither of the two Cosmos-based projects appeared to identify or disclose the loss. The issue only came into view after the Nomic protocol was halted, prompting Osmosis to examine its holdings.
The exploit surfaced only after Nomic was halted
In a September 9, 2026 post, Osmosis wrote: "Recently, we became aware of an exploit on the Nomic chain. The exploit allowed the attacker to double-spend nBTC, allowing them to send false vouchers to Osmosis. Osmosis and IBC were not compromised, as the bug was in a custom forwarding mechanism on Nomic."
Protos said the attacker combined two separate bugs to generate a transaction that "minted 40.650602 BTC of nBTC on Osmosis with no BTC behind it."
One factor that limited the damage for Osmosis was that the attacker left a sizable portion of the proceeds untouched in the form of allBTC. That balance was frozen earlier this week through what Osmosis described as an "emergency upgrade."
22.65 allBTC frozen, but part of the funds was cashed out
The report said the exploiter still managed to cash out roughly $1 million at the time by sending 671 ETH to Tornado Cash through Ethereum.
A post on the project’s governance forum sets out how Osmosis wants to cover the 40 BTC shortfall in allBTC backing. In addition to seizing the 22.65 allBTC frozen in the attacker’s account, the proposal calls for canceling a "pending liquidity re-deployment" of USDC.noble and pulling more allBTC from a Community Pool.
Signs of limited maintenance at Nomic
Protos said Nomic does not appear to be under active maintenance. The project’s X account last posted in 2024, and its GitHub recorded its last commit two years ago.
Disclosure practices in the Cosmos ecosystem draw renewed scrutiny
Osmosis, a decentralized exchange, and Nomic, a bridge, are both part of the broader Cosmos ecosystem. Protos noted that the ecosystem was recently hit by another series of incidents tied to an unrelated bug in a widely used Cosmos EVM module.
That timeline was shorter than the one tied to the nBTC exploit, but Cosmos Labs still faced criticism over how it disclosed the bug. One affected project, KiiChain, called its loss "avoidable" and said publishing a critical security fix before notifying affected teams effectively "hands the vulnerability to anyone reading the commit."

