Blockchain company Illusory Systems, which trades as Nomad, has agreed to repay users who lost funds in a 2022 cyberattack under a proposed settlement with the US Federal Trade Commission (FTC).
The regulator alleges that Nomad misled users about the security of its cryptocurrency bridge, which was compromised in an attack that resulted in the theft of $186 million. While some funds were later recovered, customers are said to have ultimately lost around $100 million.
According to the FTC, the incident stemmed from a software update pushed by Nomad in June 2022 that contained inadequately tested code. The update allegedly introduced a significant vulnerability, which was exploited roughly a month later. The FTC said the company failed to identify or mitigate the flaw before it was used in the attack.
Under the proposed settlement agreement, published this week, Nomad would be required to repay approximately $37.5 million to affected users who remain out of pocket. The repayments would need to be completed within one year of the agreement being signed, or within 30 days of the conclusion of any related litigation, whichever is later.
In addition to financial restitution, the settlement would impose a number of operational requirements on the company. Nomad would be required to establish and maintain a comprehensive cybersecurity programme, appoint a dedicated employee responsible for overseeing that programme, and submit to regular third-party security assessments. The agreement would also prohibit the company from making any future misrepresentations about the security of its products.
The FTC’s complaint alleges that Nomad promoted its blockchain bridge as a “security-first” product, despite failing to meet basic cybersecurity standards. The regulator claims the company did not adopt secure coding practices, lacked a vulnerability management programme, and failed to deploy safeguards that could have reduced the impact of a breach. It also alleges that inadequate incident response capabilities contributed to the scale of the losses suffered by users.
Nomad has agreed to the terms of the proposed settlement, which will become final following a public comment period and a second, final vote by the FTC.
“The FTC Act requires companies to take reasonable security measures,” said Christopher Mufarrige, director at the FTC’s Bureau of Consumer Protection. “It’s important that companies live up to their security promises to consumers.”
Nomad currently has a minimal public presence. The company has not issued public communications since 2023, and its website does not provide contact information or updates regarding its operations.