Alby and Nomic Hit by Security Exploits as Crypto Funds Face New Risks

10-Sep-2026 Crypto Economy

TL;DR:

  • Alby confirmed a vulnerability in versions v1.7.0 through v1.18.5 of self-hosted Alby Hub, with at least one affected user reported.
  • An attacker executed a double-spend of nBTC via a flaw in Nomic chain’s forwarding mechanism to Osmosis.
  • Osmosis validators carried out an emergency upgrade that froze 22.65 BTC in the exploiter’s address.

During Wednesday’s session, the decentralized ecosystem logged two critical security alerts when Alby and Nomic suffered operational breaches, putting funds at risk and prompting immediate technical mitigation measures.

 

Both events exposed structural risks across self-custody tools and cross-chain interoperability architectures. Development teams across both platforms deployed urgent patches and financial containment actions to safeguard community assets.

Osmosis validators froze 22.65 BTC following an exploit on the Nomic chain

Alby Hub Flaw and Double-Spend Attack on Nomic Chain

Alby reported that the vulnerability identified in its self-hosted Hub software affects versions ranging from v1.7.0 to v1.18.5. According to Alby’s technical report, the flaw is only triggered if the user’s administrative application programming interface (API) remains publicly exposed to the internet.

If an attacker gains access to this external interface, they obtain the technical capability to transfer assets out of the wallet without authorization. The company confirmed that Alby Cloud Hub infrastructure remained unaffected by the incident.

According to statements from the Alby team, security researchers from Team Red and Project Loupe formally disclosed the vulnerabilities for remediation. The software developer urged node operators to upgrade to version 1.24.0, restrict public traffic using firewalls, and update their unlock credentials immediately.

In parallel, decentralized exchange platform Osmosis reported an exploit targeting the Nomic network, which issues the wrapped asset nBTC. According to technical details disclosed by Osmosis, the attacker identified a flaw in a custom forwarding mechanism within Nomic, enabling them to forge proofs and execute a double-spend of the asset onto Osmosis.

Official documentation from Osmosis clarified that the underlying chain and the Inter-Blockchain Communication (IBC) protocol did not experience operational disruptions. However, financial exposure was significant: 39.84 nBTC of the total minted supply backed the Alloyed BTC asset, accounting for roughly 36% of its total reserves at the time of the breach.

Governance Response and Liquidity Containment on Osmosis

Following the detection of abnormal fund flows, the Osmosis moderation subDAO temporarily suspended deposits and withdrawals linked to Nomic and the Alloyed BTC liquidity pool.

Subsequently, network validators coordinated an emergency software upgrade. This coordinated action effectively froze 22.65 BTC held in the address tied to the exploiter.

Data from the core Osmosis team indicates that mitigation will require treasury backing to prevent systemic imbalances. Developers announced they will submit a community proposal to cover the remaining deficit using Bitcoin reserves from the community pool, fully restoring parity for Alloyed BTC.

The next verifiable milestone to resolve the incident will be the submission and voting on the Osmosis governance proposal to formally confiscate the 22.65 BTC frozen in the attacker’s address.

Also read: Consensys to Separate MetaMask and Launch Institutional Blockchain Unit
WHAT'S YOUR OPINION?
Related News