Illusory Systems Inc., a Utah-based company doing business as Nomad, faces action from consumer-protection regulators for failing to implement adequate data security measures that allowed hackers to exploit a code vulnerability and steal $186 million from consumers in 2022.DOCUMENTED
Nomad operates a "cross-chain bridge" platform that lets users transfer digital messages and crypto assets between different blockchain networks — infrastructure that, according to the complaint, the company marketed as "security-first" despite failing to follow basic secure coding practices.DOCUMENTED
- Hackers exploited a vulnerability Nomad introduced into its code in June 2022, stealing $186 million.
- The exploit began just over a month after the vulnerable code was introduced.
- The complaint alleges Nomad failed to implement processes for addressing vulnerability reports.
- The final order requires Nomad to implement a comprehensive information security program for 10 years.
- The company must also work to return money recovered from the breach to affected consumers.
A vulnerability that sat exposed for weeks
According to the complaint, in June 2022 Nomad introduced code containing a significant vulnerability into its smart contract offering. Hackers began exploiting that vulnerability just over a month later, ultimately draining $186 million in crypto assets from the platform.DOCUMENTED Regulators allege the company failed to use secure coding practices, did not implement a process for addressing vulnerability reports, and did not use technologies that could have reduced the risk of consumer losses once the flaw existed.DOCUMENTED
The complaint charges that Nomad's conduct violated the FTC Act's prohibition on unfair and deceptive practices in two distinct ways: first, by failing to employ reasonable and appropriate software development practices, and second, by misrepresenting the extent to which it had actually implemented the "security-first" practices its marketing described.DOCUMENTED
The gap between marketing and reality
Nomad's "security-first" branding is central to the case: the complaint alleges the company's public claims about its secure development practices were not accurate, meaning consumers who chose to use the platform based on those specific security representations were relying on a promise the company had not actually kept.REVIEWED Although the company did recover some of the stolen funds following the exploit, the complaint states that consumers nonetheless lost money that was never returned.DOCUMENTED
What the settlement requires
The proposed order bars Nomad from misrepresenting the extent to which it employs reasonable and appropriate software development practices, and from misrepresenting the extent to which it secures consumers' financial assets.DOCUMENTED It requires the company to implement a comprehensive information security program, subject to independent third-party assessment, over a 10-year term — the same duration regulators have applied to other technology-security consent orders in recent years.DOCUMENTED
The vulnerability sat in Nomad's code for just over a month before hackers found and exploited it — draining $186 million from a platform marketed as "security-first."
Part of a broader crypto and fintech security push
The Nomad case was announced alongside a separate action against Illuminate Education, an education-technology company, reflecting a period of concentrated regulatory attention to companies across different industries whose inadequate data-security practices led to major breaches affecting large numbers of consumers.REVIEWED Regulators have increasingly applied ordinary consumer-protection principles — requiring companies to actually implement the security practices they claim to follow — to the cryptocurrency and decentralized-finance space, treating a "security-first" marketing claim the same way they would treat any other unsubstantiated product claim.REVIEWED
Why cross-chain bridges carry particular risk
Cross-chain bridge platforms like Nomad occupy a uniquely exposed position in the cryptocurrency ecosystem: because they must hold and manage assets moving between otherwise incompatible blockchain networks, they typically concentrate large pools of value in a single smart contract, making any coding vulnerability in that contract a potentially catastrophic single point of failure rather than a contained, isolated bug.REVIEWED The scale of the loss in this case — $186 million exploited within roughly a month of the flawed code's introduction — illustrates how quickly a single coding oversight can compound into a major financial loss when it sits inside infrastructure managing that much concentrated value.REVIEWED
What the return-of-funds requirement means in practice
Beyond the forward-looking security requirements, the order's directive that Nomad work to return money recovered from the breach to affected consumers addresses a complication specific to cryptocurrency theft: unlike a conventional bank fraud case where stolen funds can often be traced and frozen through the traditional banking system, recovering stolen crypto assets typically depends on cooperation from exchanges, blockchain analytics firms, and sometimes the hackers themselves negotiating a partial return in exchange for avoiding prosecution.REVIEWED That recovery process, and the eventual distribution of any recovered funds back to the specific consumers who lost money, can take considerably longer to resolve than the underlying security-practice violations the settlement otherwise addresses.REVIEWED
For consumers using any cross-chain bridge or similar crypto infrastructure, the case underscores that marketing claims about security — however confidently stated — are not a substitute for independently verifying a platform's actual track record and third-party security audits before committing significant funds.REVIEWED
The case also illustrates a broader shift in how consumer-protection regulators approach the cryptocurrency industry: rather than treating decentralized-finance platforms as existing outside the reach of ordinary consumer-protection law, the Nomad settlement applies the same unfair-and-deceptive-practices framework used against conventional software and financial-services companies, holding a crypto infrastructure provider to the same evidentiary standard for its security claims as any other technology vendor.REVIEWED
That approach matters because the crypto industry has historically argued, in various contexts, that its decentralized and rapidly evolving technology should be evaluated under different or looser standards than conventional financial services. The Nomad case rejects that framing for at least one core question: whether a company's public statements about its own security practices match what it actually does. On that question, the settlement treats a blockchain infrastructure provider no differently than it would treat any bank, retailer, or software vendor making similar claims about protecting customer assets or data.REVIEWED Consumers navigating the broader decentralized-finance landscape can take the Nomad case as a signal that regulators are actively watching this sector for the same kinds of deceptive practices found across more established industries.REVIEWED
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.