Alexander Gurevich
Dual Russian-Israeli national whom U.S. prosecutors identify as the first person to exploit the Nomad bridge in August 2022 (taking ~$2.89M and triggering the ~$190M free-for-all). Indicted in 2023; arrested in Israel in May 2025 while fleeing under a new name, and approved for extradition.
Also known as: Alexander Block
Note: Gurevich is charged and awaiting extradition; the allegations have not been adjudicated.
Bio
Alexander Gurevich, a dual Russian-Israeli citizen, is named by U.S. prosecutors as the first person to exploit a critical flaw in the Nomad token bridge on August 1, 2022, withdrawing about $2.89 million in tokens. His exploit was rapidly copied by hundreds of others, draining nearly all of Nomad's ~$190 million. Days later he allegedly contacted Nomad's CTO on Telegram under a false name, apologized, returned a small portion, and sought a "reward." [1][2]
Status
A federal grand jury in the Northern District of California indicted Gurevich on eight counts (including computer fraud and money laundering) on August 16, 2023. He was arrested at Israel's Ben-Gurion Airport on May 1, 2025 while attempting to fly to Russia after legally changing his name to "Alexander Block"; Israeli courts approved his extradition to the U.S. [1][2]
Bracketed numbers refer to the numbered sources listed below.
Sources (2)
See also
Luke BelmarIndividualsCryptocurrency influencer Luke Belmar (@lukebelmar on X) became the subject of controversy following allegations related to the promotion of a memecoin. Critics on social media alleged that Belmar used a series of posts referencing a forthcoming cryptocurrency project and a large-scale airdrop to generate interest in a token without explicitly identifying a specific contract address. Belmar published multiple posts discussing an upcoming memecoin, describing plans for what he characterized as a major airdrop and making comparisons to other cryptocurrency projects. Because no contract address was publicly provided, several tokens emerged claiming association with his statements. Critics alleged that this ambiguity enabled speculation around multiple tokens while avoiding a direct endorsement of any particular asset.
Gala Games exploitTokensOn May 20, 2024 an attacker abused a privileged minter account on the GALA token contract to mint 5 billion GALA (≈$200M+ nominal) and dumped ~600M of them for ~$22M of ETH before Gala froze the address. Gala Games called it an internal access-control failure; the attacker later returned the ~$22M.
This page was last updated on Jun 15, 2026. View revision history.
