Illusory A.I CyberSecurity Scoring
Illusory
Company Information
Website:https://illusory.io
Employees number:4
Number of followers:34
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:illusory.io
Illusory Risk Score (AI oriented)
Between 700 and 749
IllusoryTechnology, Information and Internet
Updated:
31/03/2026
31/03/2026
745/1000
Moderate
Ba
Illusory Global Score (TPRM)
xxxx
IllusoryTechnology, Information and Internet
Score locked

IllusoryModerate
Current Score
745Ba (MODERATE)
01000
1 incidents
-26 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
746
MAY 2026
745
APRIL 2026
745
MARCH 2026
745
FEBRUARY 2026
744
JANUARY 2026
744
DECEMBER 2025
768
Vulnerability
16 Dec 2025 • Illusory
Illusory Systems: Illusory Systems settles with FTC over 2022 cryptocurrency hack
Nomad Token Bridge Cryptocurrency Heist
742
CRITICAL-26
ILL1766547459
FTC Orders Nomad to Return Stolen Funds and Overhaul Security After $186M Crypto Hack
The Federal Trade Commission (FTC) has reached a settlement with Illusory Systems (operating as Nomad), requiring the company to return recovered funds to victims and implement sweeping security reforms following a 2022 hack that drained $186 million in cryptocurrency from users. The breach exploited a vulnerability in Nomad’s Token Bridge, a smart contract solution designed to transfer assets across blockchains.
The FTC’s investigation found that Nomad misrepresented its security practices, advertising its platform as “high security” and “security first” while failing to implement basic safeguards. In June 2022, the company deployed untested code after a security audit, and by July 2022, hackers exploited the flaw to steal funds. White hat hackers later secured $37 million of the stolen assets, which Nomad must now return to users.
Key security failures included:
- No adequate testing—Engineers prioritized functionality over security, with minimal unit testing before deployment.
- Lack of monitoring—The company had no automated fraud detection, learning of the breach from a social media post rather than internal alerts.
- No kill switch—Without circuit breakers or emergency protocols, security teams were unable to halt the attack until after funds were drained.
- Understaffed security—Nomad lacked dedicated security personnel, clear vulnerability reporting, and a written security plan.
Internal communications revealed warnings from engineers about weak code testing and previous incidents where the company refused to reimburse users for losses caused by bugs. Despite marketing its platform as secure, executives acknowledged in private that the system was “free-to-use” with no guarantees of safety.
As part of the settlement, Nomad must develop a comprehensive cybersecurity program, address flaws identified by the FTC, and submit to third-party assessments. The FTC emphasized that companies must “live up to their security promises” under the FTC Act. The case underscores the risks of cross-chain bridges, which have become prime targets for cybercriminals due to their high-value transactions.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
768
OCTOBER 2025
768
SEPTEMBER 2025
768
AUGUST 2025
768
JULY 2025
768
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Illusory ??
What was Illusory's A.I Rankiteo Cyber Score in May 2026 ??
What was Illusory's A.I Rankiteo Cyber Score in April 2026 ??
What was Illusory's A.I Rankiteo Cyber Score in March 2026 ??
What was Illusory's A.I Rankiteo Cyber Score in February 2026 ??
What was Illusory's A.I Rankiteo Cyber Score in January 2026 ??
What was Illusory's A.I Rankiteo Cyber Score in December 2025 ??
What was Illusory's A.I Rankiteo Cyber Score in November 2025 ??
What was Illusory's A.I Rankiteo Cyber Score in October 2025 ??
What was Illusory's A.I Rankiteo Cyber Score in September 2025 ??
What was Illusory's A.I Rankiteo Cyber Score in August 2025 ??
What was Illusory's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Illusory's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Illusory ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Illusory's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?