The Federal Trade Commission (FTC) has reached a settlement with Illusory Systems, operating as Nomad, following a 2022 cyberattack that exploited a vulnerability in the company's Token Bridge cryptocurrency bridge. The attack resulted in the theft of approximately $186 million in digital assets, with customers ultimately losing around $100 million after partial recoveries. The FTC alleged that Nomad misrepresented the security of its product and introduced inadequately tested code that led to the breach. As part of the immediate response, Nomad launched a white hat bounty program, offering legal amnesty and a 10% reward to attackers who returned at least 90% of the stolen funds.
Under the proposed FTC settlement, Nomad is required to repay about $37.5 million to affected users, implement a comprehensive security program, and undergo regular third-party security assessments. The company is also barred from making further misrepresentations about its product security. The FTC emphasized the importance of companies upholding their cybersecurity promises and taking reasonable measures to protect consumers from theft and fraud, highlighting the regulatory consequences of failing to secure blockchain infrastructure.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
In December 2025, the FTC announced a proposed order against Illusory Systems requiring it to distribute about $37.5 million in recovered funds to affected users, stop misrepresenting its security, implement a comprehensive cybersecurity program, and undergo independent third-party assessments. The proposed settlement was opened for a 30-day public comment period before final approval.
Following the hack, the FTC concluded that Illusory Systems misrepresented Nomad's security and failed to implement reasonable safeguards, including secure coding, vulnerability management, staffing, testing, and incident response. The agency also said the company ignored internal and external security warnings.
After the breach, Nomad offered legal amnesty and a 10% reward to parties who returned at least 90% of stolen assets. The effort helped recover some funds, though roughly $100 million remained unrecovered.
In 2022, threat actors exploited the vulnerability in Nomad's cryptocurrency bridge, leading to the theft of about $186 million in user funds. The breach became one of the major crypto theft incidents tied to a smart contract security failure.
In June 2022, Illusory Systems introduced a significant vulnerability into Nomad's Token Bridge smart contract through inadequately tested code. The FTC later alleged the company lacked secure coding practices and adequate testing controls when the flaw was added.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.