Nemo Protocol revealed a $2.6 million exploit because of the deployment of code without an audit. The attack has raised fundamental flaws, which have raised security alarms in DeFi. Nemo Protocol also recently reported a security breach of $2.6 million caused by unaudited code used by one of their internal developers earlier this year.  The […] The post Nemo Protocol Exploit: Unvetted Code Lost Nemo $2.6M. appeared first on Live Bitcoin News.Nemo Protocol revealed a $2.6 million exploit because of the deployment of code without an audit. The attack has raised fundamental flaws, which have raised security alarms in DeFi. Nemo Protocol also recently reported a security breach of $2.6 million caused by unaudited code used by one of their internal developers earlier this year.  The […] The post Nemo Protocol Exploit: Unvetted Code Lost Nemo $2.6M. appeared first on Live Bitcoin News.

Nemo Protocol Exploit: Unvetted Code Lost Nemo $2.6M.

Nemo Protocol revealed a $2.6 million exploit because of the deployment of code without an audit. The attack has raised fundamental flaws, which have raised security alarms in DeFi.

Nemo Protocol also recently reported a security breach of $2.6 million caused by unaudited code used by one of their internal developers earlier this year. 

The decentralized finance (DeFi) platform is based on the Sui blockchain, dedicated to yield tokenization and trading. 

The attack occurred on the 7th of September, and it relied on two severe vulnerabilities that were not detected as a result of a lack of auditing and control.

Unpacking the Breach: What Went Wrong?

Several weaknesses in the codebase were the source of the breach. One of them was a flash loan feature that was accidentally leaked. 

The other was a query function bug that allowed modifications to the internal state of the contract to be made illegally. 

There were security vulnerabilities that enabled hackers to compromise the smart contract, looting the assets of Nemo in the SY/PT liquidity pool.

This was deteriorated by a governance construct that was based on a single-signature address.  The unaudited code was deployed using this model by-passing the critical internal reviews. 

Additionally, the success of the exploit was facilitated by the fact that security experts sounded warning bells in August, but these were not taken seriously.

Trail of the Stolen Funds and Remedial Actions

The stolen assets were soon removed from the Sui network using the Wormhole CCTP bridge into Ethereum following the attack, making them difficult to recover. 

The majority of the $2.6 million is in one wallet address that security teams are looking at. Nemo Protocol has ceased smart contract updates permanently, and filed code patched with an emergency audit. 

They are also collaborating with blockchain security professionals to track stolen tokens and to plot user compensation.

A bitter experience about the risks of releasing untested or unthoroughly coded products in a fast-moving DeFi industry.

 The inability of Nemo to vett and confirm new contract features highlighted the importance of being more stringent with security controls within blockchain platforms.

The post-mortem of Nemo Protocol was published in detail on September 11 and pointed to the cause, as well as the mitigation measures still in progress. 

The case contributes to the rising alarm regarding the weakness of DeFi platforms, particularly those platforms that emphasize fast-moving innovation over well-being.

 

Market Opportunity
DeFi Logo
DeFi Price(DEFI)
$0.000525
$0.000525$0.000525
+0.57%
USD
DeFi (DEFI) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23
Will XRP Price Increase In September 2025?

Will XRP Price Increase In September 2025?

Ripple XRP is a cryptocurrency that primarily focuses on building a decentralised payments network to facilitate low-cost and cross-border transactions. It’s a native digital currency of the Ripple network, which works as a blockchain called the XRP Ledger (XRPL). It utilised a shared, distributed ledger to track account balances and transactions. What Do XRP Charts Reveal? […]
Share
Tronweekly2025/09/18 00:00
Exclusive interview with Smokey The Bera, co-founder of Berachain: How the innovative PoL public chain solves the liquidity problem and may be launched in a few months

Exclusive interview with Smokey The Bera, co-founder of Berachain: How the innovative PoL public chain solves the liquidity problem and may be launched in a few months

Recently, PANews interviewed Smokey The Bera, co-founder of Berachain, to unravel the background of the establishment of this anonymous project, Berachain's PoL mechanism, the latest developments, and answered widely concerned topics such as airdrop expectations and new opportunities in the DeFi field.
Share
PANews2024/07/03 13:00