MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Nemo Protocol says unaudited code deployment led to $2.6 million exploit
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$71,448.001.22%
  • ethereumEthereum(ETH)$2,104.591.26%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$659.991.10%
  • rippleXRP(XRP)$1.410.90%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$88.211.04%
  • tronTRON(TRX)$0.2963020.80%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-1.91%
  • dogecoinDogecoin(DOGE)$0.0956181.04%
Blockchain Security

Nemo Protocol says unaudited code deployment led to $2.6 million exploit

Last updated: September 11, 2025 12:20 pm
Published: 6 months ago
Share

The team is collaborating with security teams on Sui to trace the funds and is developing a compensation plan for affected users.

Sui-based DeFi platform Nemo Protocol said its $2.6 million exploit earlier this month resulted from two vulnerabilities that were introduced into the code by a developer and deployed without proper audits.

In a post-mortem report published late Wednesday night, Nemo explained that the Sept. 7 attack was caused by two issues: an internal flash loan function that was mistakenly exposed to the public, and a flaw in a query function that allowed unauthorized state changes within the contract.

According to the report, the vulnerabilities date back to January of this year. After receiving the initial audit report from blockchain security firm MoveBit, one Nemo developer introduced these new, unaudited features into the codebase. The version of the contract containing this code was then deployed to the mainnet.

“The governance root cause was the protocol’s reliance on a single-signature address for upgrades, which failed to prevent the deployment of code that had not undergone rigorous scrutiny,” the report said, adding that the team failed to act on a warning from the Asymptotic security team in August regarding a separate but related vulnerability.

The attacker used the combination of the flash loan and the state-modifying query function to manipulate the internal state of the contract, draining “substantial” assets from the SY/PT liquidity pool. The stolen funds were moved from the Sui network to Ethereum via Wormhole CCTP, with the majority of the assets currently remaining in a single address.

Nemo Protocol said it has since paused its core functions, patched the vulnerabilities, and submitted the updated code for an emergency audit. The team is collaborating with security teams on Sui to trace the funds and is developing a compensation plan for affected users.

“Despite multiple audits and safeguards, we acknowledge that we allowed ourselves to rely too heavily on past assurances, rather than maintaining uncompromising scrutiny at every step,” Nemo said in the report.

Nemo Protocol is a yield infrastructure and native yield-trading platform built on Sui, designed to improve DeFi interactions. It focuses on yield tokenization, enabling users to trade, hedge, or leverage yields more efficiently.

Read more on The Block

This news is powered by The Block The Block

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

I will never do a coin”: Moltbot Founder Slams Crypto Scam Frenzy
North Korean crypto hacks escalate in record year of theft and laundering
ProVisionary Pty Ltd Marks First-Year Milestone With 1,000 Active Australian Clients as Demand for Intelligence-Driven Blockchain Security Accelerates
SwissBorg Hit by $41.5M Solana Hack via API Exploit – TokenPost
Victims lost $2.37B in 121 crypto hacks in first half of 2025: SlowMist

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Polygon rolls out hard fork to resolve bug causing 15-minute transaction finality delay
Next Article Avalanche plans to launch an AVAX treasury company with $1 billion in funding
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d