bitcoin
Bitcoin (BITCOIN)
$114,442 0.66%
ethereum
Ethereum (ETHEREUM)
$4,420 0.90%
binancecoin
BNB (BINANCECOIN)
$895.51 -0.04%
solana
Solana (SOLANA)
$227.89 2.15%
ripple
XRP (RIPPLE)
$3.00 0.24%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000013 0.22%
pepe
Pepe (PEPE)
$0.000010 0.12%
bonk
Bonk (BONK)
$0.000024 2.93%
bitcoin
Bitcoin (BITCOIN)
$114,442 0.66%
ethereum
Ethereum (ETHEREUM)
$4,420 0.90%
binancecoin
BNB (BINANCECOIN)
$895.51 -0.04%
solana
Solana (SOLANA)
$227.89 2.15%
ripple
XRP (RIPPLE)
$3.00 0.24%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000013 0.22%
pepe
Pepe (PEPE)
$0.000010 0.12%
bonk
Bonk (BONK)
$0.000024 2.93%
bitcoin
Bitcoin (BITCOIN)
$114,442 0.66%
ethereum
Ethereum (ETHEREUM)
$4,420 0.90%
binancecoin
BNB (BINANCECOIN)
$895.51 -0.04%
solana
Solana (SOLANA)
$227.89 2.15%
ripple
XRP (RIPPLE)
$3.00 0.24%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000013 0.22%
pepe
Pepe (PEPE)
$0.000010 0.12%
bonk
Bonk (BONK)
$0.000024 2.93%
Disclosure
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
Nemo Protocol Loses $2.6M After Developer Deploys Unaudited Smart Contract

Highlights:

  • A single developer deployed unaudited code that enabled the $2.6M exploit on Nemo Protocol.
  • The flash loan and query vulnerabilities were introduced after the audit.
  • The funds were bridged to Ethereum, with $2.4M still in a hacker’s wallet.

On Sept. 8, attackers exploited two smart contract flaws in Nemo Protocol, draining $2.6 million from the funds of users. According to the post-mortem report, the cause of the incident was due to an unaudited rogue developer injecting unaudited features into the mainnet codebase. These features included a flash loan function mistakenly set as public and a query method with the ability to perform unauthorized state changes.

Advertisement

Banner

The vulnerabilities gave hackers the ability to mint additional SY tokens and manipulate pool prices, ultimately draining liquidity. Within minutes, the attackers were able to bridge assets stolen from the Sui network to Ethereum using Wormhole’s CCTP bridge. Around $2.4 million is still held in one Ethereum wallet associated with the exploit.

Governance Gaps and Unapproved Code in Nemo Protocol

The root of the incident goes back to January 2025. After receiving an initial audit from MoveBit, a developer merged previously audited fixes with new and unverified features. These new elements, however, were never disclosed through the audit process. The developer deployed the modified version with a single-signature address, a governance structure without safeguards for internal approval.

By skipping the peer review process, the developer contributed live vulnerabilities to the mainnet of the Nemo Protocol. This unauthorized contract continued to exist despite the project’s transition to a multi-signature upgrade model in April. Moreover, internal monitoring failed to detect the differences between the audited and deployed versions of the code.

Further warnings came in August when a related flaw was flagged by security firm Asymptotic. Despite the available support, the developer ignored the alert and did not make any changes. This failure to act contributed directly to the successful conduct of the attack of September.

Exploit Execution, Response, and Recovery

The exploit commenced at 16:00 UTC on September 8. Attackers used the exposed flash loan function in conjunction with the faulty method of the query to manipulate the contract behavior. These changes consequently enabled the generation of false yield situations and enabled excessive token minting. Arbitrageurs drained the SY/PT pool still further before the team froze core functions.

Unusual returns in YT pools of more than 30x alerted the Nemo team within 30 minutes. Immediate action followed, including halting protocol operations, patching the code and launching emergency audits. The team also contacted centralized exchanges to aid in the tracing and potential freezing of stolen assets.

To compensate for user losses, Nemo Protocol is working on a compensation plan to structure debt. It includes tokenomic adjustments that will be shared with the community prior to release. Meanwhile, monitoring systems have been upgraded, while security partnerships have been expanded across the Sui ecosystem.

The team stressed that future upgrades will only go through multi-signature wallets and audit checkpoints will be more rigorous. In addition, a white-hat bounty program has been implemented to aid further recovery and decrease risks in the future.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

Advertisement

Banner

Advertisement

Banner