Immunefi
Published in

Immunefi

Hack Analysis: Nomad Bridge, August 2022

Introduction

Background

Root Cause

Snippet 1: process function on Replica.sol
Snippet 2: initialize function in Replica.sol

Proof of Concept

The Attack

Snippet 3: The start of our attack contract
Snippet 4: Generate the malicious message with the right format and parameters

Conclusion

Snippet 5: all code

--

--

Immunefi is the premier bug bounty platform for smart contracts and DeFi projects, where security researchers review code, disclose vulnerabilities, get paid, and make crypto safer. Immunefi removes security risk through bug bounties and comprehensive security services.

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Immunefi

Immunefi is the premier bug bounty platform for smart contracts, where hackers review code, disclose vulnerabilities, get paid, and make crypto safer.