Nemo Protocol, a DeFi yield platform built on the Sui blockchain, has been hit by an exploit that drained millions in stablecoins.  PeckShieldAlert first flagged the breach on September 8, posting on X that roughly $2.4 million in USDC had…Nemo Protocol, a DeFi yield platform built on the Sui blockchain, has been hit by an exploit that drained millions in stablecoins.  PeckShieldAlert first flagged the breach on September 8, posting on X that roughly $2.4 million in USDC had…

Sui-based Nemo Protocol exploited for $2.4m

2025/09/08 20:24

Nemo Protocol, a DeFi yield platform built on the Sui blockchain, has been hit by an exploit that drained millions in stablecoins. 

Summary
  • Nemo Protocol was exploited for $2.4 million, resulting in its TVL plunging from over $6 million to about $1.5 million.
  • Cetus Protocol on Sui was similarly hacked in May, with $162M frozen on-chain and $60M bridged out, marking another major exploit on the network this year.
  • DeFi hacks have surged in 2025, with $2.37 billion lost in the first half of the year.

PeckShieldAlert first flagged the breach on September 8, posting on X that roughly $2.4 million in USDC had been stolen from Nemo. The attacker quickly bridged the stolen funds from Arbitrum to Ethereum, according to the blockchain security firm’s analysis. 

Nemo confirmed the attack in a tweet shortly after, adding that an investigation is underway to determine the cause of the breach. The protocol also suspended all smart contract activity in the meantime.

The fallout was immediate. Data from DeFiLlama shows that Nemo’s total value locked (TVL) plunged to about $1.53 million, down sharply from more than $6 million before the attack. The exploit targeted the protocol’s yield-trading system, which allows users to split staked assets into Principal Tokens (PTs) and Yield Tokens (YTs) in order to speculate on future returns.

Questions have arisen around the exact cause of the breach, and the scale of the losses has already rattled the protocol’s community.

The attack gives fresh urgency to broader concerns around security on Sui, coming just months after another major protocol, Cetus, was similarly compromised.

Nemo hack marks second major exploit on Sui in 2025

Just months before the Nemo hack, another major incident rocked the Sui blockchain. On May 22, Cetus Protocol, a leading decentralized exchange and liquidity provider, was exploited for $223 million. The attacker exploited an arithmetic overflow vulnerability in a third-party math library, draining funds in under 15 minutes.

Sui validators and ecosystem partners quickly froze about $162 million of the stolen assets on-chain, and $60 million was bridged out to Ethereum. Cetus suspended its smart contracts and initiated a recovery plan that included a $6 million bounty, as well as talks of a “whitehat settlement” offering the attacker amnesty if remaining funds were returned.

These high-profile breaches are part of a broader surge in DeFi-targeted attacks throughout 2025. According to SlowMist’s mid-year report, the blockchain industry suffered over $2.37 billion in losses from 121 security incidents in the first half of the year, with DeFi accounting for 76% of those incidents, though centralized exchanges suffered larger dollar losses overall.

A separate analysis from Hacken’s 2025 mid-year security report puts total crypto industry losses at over $3.1 billion in the first six months. Access control failures like misconfigured wallets and legacy keys accounted for 59% of those losses, while DeFi-specific smart-contract vulnerabilities like the Cetus bug made up $263 million, or about 8%.

Hackers continue to zero in on DeFi protocols across multiple chains, and the Sui ecosystem is no exception. With two major exploits already this year in Cetus and Nemo, it remains to be seen whether new security measures can keep pace with the rising sophistication of attacks.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Tokenization Key to Modernizing US Markets

Tokenization Key to Modernizing US Markets

The post Tokenization Key to Modernizing US Markets appeared on BitcoinEthereumNews.com. The Strategy: SEC Chair Paul Atkins designates “tokenization” as the industrial strategy to modernize US capital markets, launching the “Project Crypto” initiative. The Rules: A new “Token Taxonomy” will legally separate Digital Commodities, Collectibles, and Tools from Securities, ending the “regulation by enforcement” era. The Privacy: The SEC’s Dec 15 roundtable will feature Zcash founder Zooko Wilcox, signaling a potential policy thaw on privacy-preserving infrastructure. Securities and Exchange Commission (SEC) Chair Paul Atkins has formally aligned the agency’s mission with the digital asset revolution, declaring “tokenization” as the critical alpha required to modernize America’s aging capital markets infrastructure.  In a definitive signal to Wall Street, Atkins outlined the next phase of “Project Crypto,” a comprehensive regulatory overhaul designed to integrate blockchain rails into the federal securities system. Related: U.S. SEC Signals Privacy Enhancement in Tokenization of Securities U.S. SEC Chair Touts Tokenization as the Needed Element for Modernizing Capital Markets According to Chair Atkins, tokenization is the alpha needed to modernize the capital markets in the United States. As such, Chair Atkins noted that the SEC’s Project Crypto will focus on issuing clarity under the existing rules as Congress awaits passing the CLARITY  Act. Moreover, the SEC Chair believes that major global banks and brokers will adopt tokenization of real-world assets (RWA) in less than 10 years. Currently, the SEC is working closely with the sister agency Commodity Futures Trading Commission (CFTC) to catalyze the mainstream adoption of tokenized assets. Chair Atkins stated that tokenization of capital markets provides certainty and transparency in the securities industry. From a regulatory perspective, Chair Atkins stated that tokenized securities are still securities and thus bound by the existing securities laws. However, Chair Atkins stated that digital collectibles, commodities, and tools are not securities, thus not bound by the 1940s Howey test. As such,…
Share
BitcoinEthereumNews2025/12/08 18:35