Nemo Protocol revealed a $2.6 million exploit because of the deployment of code without an audit. The attack has raised fundamental flaws, which have raised security alarms in DeFi. Nemo Protocol also recently reported a security breach of $2.6 million caused by unaudited code used by one of their internal developers earlier this year.  The […] The post Nemo Protocol Exploit: Unvetted Code Lost Nemo $2.6M. appeared first on Live Bitcoin News.Nemo Protocol revealed a $2.6 million exploit because of the deployment of code without an audit. The attack has raised fundamental flaws, which have raised security alarms in DeFi. Nemo Protocol also recently reported a security breach of $2.6 million caused by unaudited code used by one of their internal developers earlier this year.  The […] The post Nemo Protocol Exploit: Unvetted Code Lost Nemo $2.6M. appeared first on Live Bitcoin News.

Nemo Protocol Exploit: Unvetted Code Lost Nemo $2.6M.

2025/09/12 16:30
2분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Nemo Protocol revealed a $2.6 million exploit because of the deployment of code without an audit. The attack has raised fundamental flaws, which have raised security alarms in DeFi.

Nemo Protocol also recently reported a security breach of $2.6 million caused by unaudited code used by one of their internal developers earlier this year. 

The decentralized finance (DeFi) platform is based on the Sui blockchain, dedicated to yield tokenization and trading. 

The attack occurred on the 7th of September, and it relied on two severe vulnerabilities that were not detected as a result of a lack of auditing and control.

Unpacking the Breach: What Went Wrong?

Several weaknesses in the codebase were the source of the breach. One of them was a flash loan feature that was accidentally leaked. 

The other was a query function bug that allowed modifications to the internal state of the contract to be made illegally. 

There were security vulnerabilities that enabled hackers to compromise the smart contract, looting the assets of Nemo in the SY/PT liquidity pool.

This was deteriorated by a governance construct that was based on a single-signature address.  The unaudited code was deployed using this model by-passing the critical internal reviews. 

Additionally, the success of the exploit was facilitated by the fact that security experts sounded warning bells in August, but these were not taken seriously.

Trail of the Stolen Funds and Remedial Actions

The stolen assets were soon removed from the Sui network using the Wormhole CCTP bridge into Ethereum following the attack, making them difficult to recover. 

The majority of the $2.6 million is in one wallet address that security teams are looking at. Nemo Protocol has ceased smart contract updates permanently, and filed code patched with an emergency audit. 

They are also collaborating with blockchain security professionals to track stolen tokens and to plot user compensation.

A bitter experience about the risks of releasing untested or unthoroughly coded products in a fast-moving DeFi industry.

 The inability of Nemo to vett and confirm new contract features highlighted the importance of being more stringent with security controls within blockchain platforms.

The post-mortem of Nemo Protocol was published in detail on September 11 and pointed to the cause, as well as the mitigation measures still in progress. 

The case contributes to the rising alarm regarding the weakness of DeFi platforms, particularly those platforms that emphasize fast-moving innovation over well-being.

 

시장 기회
DeFi 로고
DeFi 가격(DEFI)
$0.000323
$0.000323$0.000323
-1.82%
USD
DeFi (DEFI) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!