Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Nemo Protocol says unaudited code deployment led to $2.6 million exploit

Nemo Protocol says unaudited code deployment led to $2.6 million exploit

The BlockThe Block2025/09/10 16:00
By:By Danny Park

Quick Take Nemo Protocol said it found two vulnerabilities that were deployed into the codebase without audits by a developer. The team is collaborating with security teams on Sui to trace the funds and is developing a compensation plan for affected users.

Nemo Protocol says unaudited code deployment led to $2.6 million exploit image 0

Sui-based DeFi platform Nemo Protocol said its $2.6 million exploit earlier this month resulted from two vulnerabilities that were introduced into the code by a developer and deployed without proper audits.

In a post-mortem report published late Wednesday night, Nemo explained that the Sept. 7 attack was caused by two issues: an internal flash loan function that was mistakenly exposed to the public, and a flaw in a query function that allowed unauthorized state changes within the contract.

According to the report, the vulnerabilities date back to January of this year. After receiving the initial audit report from blockchain security firm MoveBit, one Nemo developer introduced these new, unaudited features into the codebase. The version of the contract containing this code was then deployed to the mainnet. 

"The governance root cause was the protocol's reliance on a single-signature address for upgrades, which failed to prevent the deployment of code that had not undergone rigorous scrutiny," the report said, adding that the team failed to act on a warning from the Asymptotic security team in August regarding a separate but related vulnerability.

The attacker used the combination of the flash loan and the state-modifying query function to manipulate the internal state of the contract, draining "substantial" assets from the SY/PT liquidity pool. The stolen funds were moved from the Sui network to Ethereum via Wormhole CCTP, with the majority of the assets currently remaining in a single address.

Nemo Protocol said it has since paused its core functions, patched the vulnerabilities, and submitted the updated code for an emergency audit. The team is collaborating with security teams on Sui to trace the funds and is developing a compensation plan for affected users. 

"Despite multiple audits and safeguards, we acknowledge that we allowed ourselves to rely too heavily on past assurances, rather than maintaining uncompromising scrutiny at every step," Nemo said in the report.

Nemo Protocol is a yield infrastructure and native yield-trading platform built on Sui, designed to improve DeFi interactions. It focuses on yield tokenization, enabling users to trade, hedge, or leverage yields more efficiently.


0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like