Four years after the hack, the Nomad exploit is still sending shockwaves through crypto. Illustration: Gwen P; Source: ShutterstockFour years after the hack, the Nomad exploit is still sending shockwaves through crypto. Illustration: Gwen P; Source: Shutterstock

Nomad hack: Crypto advocacy groups slam FTC ‘kill switch’ proposal

2026/01/23 19:09
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Crypto trade associations in the US have slammed a complaint filed by the Federal Trade Commission that suggested a Utah-based company broke the law when it built software without a so-called kill switch.

That software, a crypto bridge called Nomad, was hacked for nearly $200 million in 2022. While its developers were able to recover millions in stolen crypto, Nomad has failed to gain any traction since it was relaunched in December that year.

Though the project is seemingly defunct, parent company Illusory Systems agreed last year to settle a complaint filed by the FTC.

The agency alleged Illusory Systems had failed to take reasonable steps to secure its software. But its definition of “reasonable and appropriate” has alarmed the crypto industry.

“The company failed to incorporate ‘circuit breakers’ or a ‘kill switch’ that could immediately cease the functioning of the Nomad Token Bridge in the presence of suspicious transactions,” the FTC wrote in the complaint, which it published alongside the proposed settlement in December.

But that technology is far from industry standard and, in some cases, could even make software more vulnerable to hackers, four crypto trade associations wrote in a letter to the agency this week.

Moreover, the presence of a kill switch implies unilateral control — an unacceptable requirement for developers attempting to build decentralised protocols, according to the letter.

The tiff is the latest example of the myriad ways in which regulators charged with protecting consumers can impose requirements limiting developers’ ability to build such software.

The Nomad hack

Crypto bridges allow users to move their crypto between otherwise incompatible blockchains. But they have proven a lucrative target for hackers.

In April 2022, Nomad said it had raised $22 million at a $225 million valuation to build “security-first interoperability.”

Despite Nomad’s assurances, just four months later some 300 hackers exploited a bug in the bridge and made off with $186 million in crypto, something the FTC attributed to “inadequately tested code.”

Last year, crypto forensics firm TRM Labs called it “one of the most remarkable and chaotic hacks in decentralised finance history.”

The company was able to recover roughly $37 million thanks to ethical hackers who joined the plunder in order to prevent thieves from running off with every last dollar. But a relaunched bridge failed to gain any traction — as of Friday, it held just $1 million in user deposits, according to DefiLlama data.

Nomad’s final post on X was more than two years ago.

The FTC has alleged that Nomad employed “unfair security practices” — such as the lack of a kill switch — that harmed its users. As such, it misled those users when it touted its “security first” approach.

The company has agreed to settle the complaint. If the complaint and settlement are finalised, Nomad will have to implement a new information security programme and return any remaining crypto it recovered after the hack, among other things.

Impossible mandate?

But industry groups say the complaint needs to be revised, as it implies a company operates unlawfully by releasing software without certain security features, including the kill switch.

That’s a problematic requirement, as it would “require privileged control or some other centralised authority to execute,” the letter reads.

“Many of these technologies — including technologies that utilise decentralised governance and control of operations — would be stifled if not outright deemed impossible under the expectations in the Proposed Complaint.”

Even MetaMask developer Consensys weighed in.

“Circuit breakers are not industry standard today, and they were not standard at the time of the Nomad incident,” Bill Hughes, senior counsel at Consensys, wrote in a letter to the agency.

Last year, police in Israel arrested dual Russian-Israeli citizen Alexander Gurevich when he attempted to travel to Russia using documents bearing a different name, according to a report from the Jerusalem Post. Gurevich was extradited to the US on suspicion of participating in the Nomad hack.

DL News could not immediately determine Thursday whether Gurevich had ultimately been charged in connection with the hack.

Aleks Gilbert is DL News’ New York-based DeFi correspondent. You can reach him at aleks@dlnews.com.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Which Crypto Hits $1 First? Comparing ADA, DOGE & This Altcoin

Which Crypto Hits $1 First? Comparing ADA, DOGE & This Altcoin

The race to the one-dollar milestone is a frequent topic of discussion in April 2026. However, the mathematical reality for each project is very different. When
Share
Techbullion2026/04/03 20:29
For Users Who Prioritize Confidentiality In Their Transactions

For Users Who Prioritize Confidentiality In Their Transactions

The post For Users Who Prioritize Confidentiality In Their Transactions appeared on BitcoinEthereumNews.com. Verge is a privacy-focused cryptocurrency and blockchain platform designed to provide anonymous and secure transactions. XVG coin review by Coinidol.com. Privacy and anonymity A project DogeCoinDark was launched in 2014 but later in 2016 it was rebranded as Verge. The project focuses on enabling private and untraceable transactions while maintaining fast transaction speeds and a user-friendly experience. Verge employs multiple privacy mechanisms, including the use of Tor and I2P networks to obfuscate users’ IP addresses and hide transaction origins, enhancing privacy and anonymity. The Wraith Protocol of the platorm is a feature that allows users to switch between public and private ledgers, giving them the option to make transactions visible or private. By utilizing a proof-of-work (PoW) consensus algorithm and implementing technologies to enhance scalability Verge aims to provide fast transaction speeds. XVG is the native cryptocurrency of the Verge network.  The atomic swaps available on Verge, allow users to exchange XVG with other cryptocurrencies without the need for intermediaries. Moreover, it offers mobile wallets that allow users to send and receive XVG on the go. Disclaimer. This article is for informational purposes only and should not be viewed as an endorsement by Coinidol.com. The data provided is collected by the author and is not sponsored by any company or token developer. They are not a recommendation to buy or sell cryptocurrency. Readers should do their research before investing in funds. Source: https://coinidol.com/verge-xvg-token/
Share
BitcoinEthereumNews2025/09/18 17:15
Bitcoin ETFs Surge with 20,685 BTC Inflows, Marking Strongest Week

Bitcoin ETFs Surge with 20,685 BTC Inflows, Marking Strongest Week

TLDR Bitcoin ETFs recorded their strongest weekly inflows since July, reaching 20,685 BTC. U.S. Bitcoin ETFs contributed nearly 97% of the total inflows last week. The surge in Bitcoin ETF inflows pushed holdings to a new high of 1.32 million BTC. Fidelity’s FBTC product accounted for 36% of the total inflows, marking an 18-month high. [...] The post Bitcoin ETFs Surge with 20,685 BTC Inflows, Marking Strongest Week appeared first on CoinCentral.
Share
Coincentral2025/09/18 02:30

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!