MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Illusory Systems settles with FTC over 2022 cryptocurrency hack
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$67,684.00-0.67%
  • ethereumEthereum(ETH)$1,998.091.48%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.480.24%
  • binancecoinBNB(BNB)$616.50-0.83%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$84.85-0.96%
  • tronTRON(TRX)$0.281853-0.75%
  • dogecoinDogecoin(DOGE)$0.1007991.25%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.38%
Smart Contracts

Illusory Systems settles with FTC over 2022 cryptocurrency hack

Last updated: December 17, 2025 5:45 am
Published: 2 months ago
Share

Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.

The Federal Trade Commission is ordering a company that publicly touted its cybersecurity capabilities to return recovered funds to victims and implement security reforms, after a software flaw let hackers steal hundreds of millions of dollars in cryptocurrencies from users.

The FTC announced it had reached a settlement with Illusory Systems, which also does business as Nomad, following an investigation into a 2022 incident where hackers exploited a vulnerability in the company’s Token Bridge cryptocurrency smart contract solution. The program provides protocols that connect different blockchains and allow users to transfer assets between them.

As part of the deal, the company must implement a comprehensive cybersecurity plan, including addressing security flaws identified in the FTC’s complaint and programs for protecting consumers from theft and fraud. It must also submit the plan and cooperate with independent third-party assessors on any improvements and return stolen money clawed back by law enforcement.

“The FTC Act requires companies to take reasonable security measures,” said Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection, in a statement. “It’s important that companies live up to their security promises to consumers.”

According to an FTC complaint, in June 2022, Illusory Systems introduced “new, inadequately tested code” for Token Bridge, its set of cryptocurrency smart contracts, following a security audit.

Just one month later, malicious hackers used the flaw to steal $186 million from users in cryptocurrency funds. White hat hackers were able to use the same exploit to safeguard at least $37 million of the stolen funds before hackers could drain them, and the agreement directs Illusory Systems to return that money to users.

The FTC focused on how Illusory Systems presented its Token Bridge network to customers, charging the company with materially misrepresenting its commitment to security to users.

At different points the company advertised the smart contract solution as “high security,” a “security first” solution that “prioritizes the safety and security of the funds/cross chain messages” and something that would “keep the entire system (and your funds/messages) safe.”

Another message simply stated: “We’re secure…period.”

But the FTC’s investigation found that Illusory Systems had failed to put in place reasonable and appropriate security practices..

Despite knowing that cross-chain bridges like Token Bridge were targeted by hackers and could result in “catastrophic loss” if compromised, developers failed to implement “well known secure coding practices, such as writing and conducting adequate unit tests prior to pushing code to production.”

In fact, company software engineers and a post-incident analysis revealed that most testing of Token Bridge focused on making sure it functioned properly, rather than verifying that it was secure.

According to the commission, Illusory Systems lacked adequate security staff, clear vulnerability reporting and response processes, a written security plan, and “widely accepted industry norms” such as circuit breakers or a “kill switch” that could halt suspicious financial transactions.

Compounding matters, the company lacked automated fraud monitoring, so it learned about the breach from a user on social media instead of detecting it internally.

Staff scrambled to respond to the hack, even relying on an engineer on a flight to relay code snippets via an online chat. The delays meant security staff were “unable to shut down the bridge until after it had been emptied of assets.”

Months before the hack, an engineer warned the CEO about weak code testing and quality assurance noting that the company had previously shipped code with a significant vulnerability because it wasn’t properly tested.

The investigation also revealed that despite promising to keep customers’ funds secure, the company previously overrode internal efforts to reimburse users who lost money when a bug in the web-based Token Bridge interface caused losses.

In one instance the chief operating officer reportedly said “there are no guarantees of safety” and the CEO noted that Illusory Systems was “putting out a free-to-use interface to a protocol that may have bugs/issues.”

Read more on CyberScoop

This news is powered by CyberScoop CyberScoop

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Early Buyers Tip MUTM as the Best Sub-$1 Pick to Beat ADA, Eyeing 28× Gains in 6 Months – Blockonomi
Brazil’s Bill Bans Algorithmic Stablecoins as Bitcoin Hyper Soars
Clear-Eyed Chronicle of a Nascent Financial Revolution
UPCX Wallet Releases New Features and Opens Testnet for Public Testing
Yaroslav Belkin Reputation Undamaged by Juan Engelbrecht MOBU: Setting the Record Straight Amid AI…

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article CSUCI Announces Channel Islands Tuition Promise for Eligible California Students Beginning Fall 2026
Next Article FTC Compels Nomad Operator to Repay Users After $186M Crypto Bridge Hack in 2022 – Decrypt
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d