Nomad Bridge: The $190M Config Bug That Became a Mob Looting
A routine upgrade left message proofs rubber-stamped. Hundreds of copycats drained the bridge in crypto’s most chaotic heist.
A routine upgrade left message proofs rubber-stamped. Hundreds of copycats drained the bridge in crypto’s most chaotic heist.
A patched OAuth endpoint answered one question too honestly: which phone belongs to which handle. The dataset sold for $30k — the class lesson is still with us.
Five thousand cloud VMs, each pushing 5,000 rps of encrypted traffic at one small website. June 2022’s record flood and the edge doctrine it sealed.
A 2-of-5 multisig guarding nine figures. Lazarus took the two keys it needed, and the bridge-custody era changed for good.
Sixteen days between disclosure and patch. Who exploited Follina in the gap, how fast state and commodity actors moved, and the doctrine it forged.
Exploited in the wild two days before the patch existed. How OGNL injection turned Confluence into June 2022’s internet-scale fire drill — and the playbook it left behind.
GitHub’s OAuth tokens lived in Heroku’s infrastructure. One compromised CI cache later, an ecosystem learned where vendor tokens really live.
No key stolen, no bug exploited — an attacker borrowed a voting majority on Aave, passed his own proposal, and drained the vaults in one block.
Conti encrypted the treasury during tax season, declared war on the government, and forced the world’s first ransomware state of emergency.
A JDK 9 property path reopened a 2010-era bug class in Spring’s data binder — and gave every Tomcat admin a very bad 48 hours.
37GB claimed, one account compromised, no customer data lost — and a DEV-0536 profile that taught the industry how social engineering beats MFA.
North Korea’s Lazarus Group drained Axie Infinity’s Ronin bridge of $625M with five forged signatures and a leftover permission nobody revoked.