The post Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits appeared on BitcoinEthereumNews.com. Sui-based yield trading protocol Nemo lost about $2.59 million due to a known vulnerability introduced by non-audited code being deployed, according to the project. According to Nemo’s post-mortem analysis of the Sept. 7 hack, a flaw in a function intended to reduce slippage allowed the attacker to change the state of the protocol. This function, named “get_sy_amount_in_for_exact_py_out,” was pushed onchain without being audited by smart contract auditor Asymptotic. Furthermore, Asymptotic’s team identified the issue in a preliminary report. Still, the Nemo team admits that its “team did not adequately address this security concern in a timely manner.” Deploying new code only required a signature from a single address, allowing the developer to push unaudited code onchain without disclosing the changes. Furthermore, he did not use the confirmation hash provided in the audit for the deployment, breaking the procedure. This is not the first time a hack was revealed to have been easily preventable. The report follows NFT trading platform SuperRare suffering a $730,000 exploit in late July due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices. Related: Bubblemaps alleges largest Sybil attack in crypto history on MYX airdrop Security procedures changed too late The vulnerable code was pushed onchain in early January. The upgrade procedure, which would likely have prevented the unaudited code from being deployed onchain, was implemented in April. Despite the upgrade, the vulnerability had already made its way into the production environment. Asymptotic warned Nemo of the vulnerability on Aug. 11, but the project said it was focused on other issues and failed to address it before the exploit. Related: Failed NPM exploit highlights looming threat to crypto security: Exec Nemo pauses protocol, prepares patch According to the analysis, Nemo’s protocol core functions are now paused to… The post Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits appeared on BitcoinEthereumNews.com. Sui-based yield trading protocol Nemo lost about $2.59 million due to a known vulnerability introduced by non-audited code being deployed, according to the project. According to Nemo’s post-mortem analysis of the Sept. 7 hack, a flaw in a function intended to reduce slippage allowed the attacker to change the state of the protocol. This function, named “get_sy_amount_in_for_exact_py_out,” was pushed onchain without being audited by smart contract auditor Asymptotic. Furthermore, Asymptotic’s team identified the issue in a preliminary report. Still, the Nemo team admits that its “team did not adequately address this security concern in a timely manner.” Deploying new code only required a signature from a single address, allowing the developer to push unaudited code onchain without disclosing the changes. Furthermore, he did not use the confirmation hash provided in the audit for the deployment, breaking the procedure. This is not the first time a hack was revealed to have been easily preventable. The report follows NFT trading platform SuperRare suffering a $730,000 exploit in late July due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices. Related: Bubblemaps alleges largest Sybil attack in crypto history on MYX airdrop Security procedures changed too late The vulnerable code was pushed onchain in early January. The upgrade procedure, which would likely have prevented the unaudited code from being deployed onchain, was implemented in April. Despite the upgrade, the vulnerability had already made its way into the production environment. Asymptotic warned Nemo of the vulnerability on Aug. 11, but the project said it was focused on other issues and failed to address it before the exploit. Related: Failed NPM exploit highlights looming threat to crypto security: Exec Nemo pauses protocol, prepares patch According to the analysis, Nemo’s protocol core functions are now paused to…

Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Sui-based yield trading protocol Nemo lost about $2.59 million due to a known vulnerability introduced by non-audited code being deployed, according to the project.

According to Nemo’s post-mortem analysis of the Sept. 7 hack, a flaw in a function intended to reduce slippage allowed the attacker to change the state of the protocol. This function, named “get_sy_amount_in_for_exact_py_out,” was pushed onchain without being audited by smart contract auditor Asymptotic.

Furthermore, Asymptotic’s team identified the issue in a preliminary report. Still, the Nemo team admits that its “team did not adequately address this security concern in a timely manner.”

Deploying new code only required a signature from a single address, allowing the developer to push unaudited code onchain without disclosing the changes. Furthermore, he did not use the confirmation hash provided in the audit for the deployment, breaking the procedure.

This is not the first time a hack was revealed to have been easily preventable. The report follows NFT trading platform SuperRare suffering a $730,000 exploit in late July due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices.

Related: Bubblemaps alleges largest Sybil attack in crypto history on MYX airdrop

Security procedures changed too late

The vulnerable code was pushed onchain in early January. The upgrade procedure, which would likely have prevented the unaudited code from being deployed onchain, was implemented in April.

Despite the upgrade, the vulnerability had already made its way into the production environment. Asymptotic warned Nemo of the vulnerability on Aug. 11, but the project said it was focused on other issues and failed to address it before the exploit.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Nemo pauses protocol, prepares patch

According to the analysis, Nemo’s protocol core functions are now paused to prevent further losses. The team is collaborating with multiple security teams and providing all relevant addresses to assist in freezing assets on centralized exchanges.

A patch has now been developed, and Asymptotic is auditing the new code. The project said it removed its flash loan function, fixed the vulnerable code and added a manual-reset feature to restore affected values. Nemo is also designing a compensation plan for users, including debt structuring at the tokenomics level.

Nemo apologized to its users and claims to have learned that “security and risk management demand constant vigilance.” The team also promised to improve its defences and apply stricter protocol control.

Magazine: North Korea crypto hackers tap ChatGPT, Malaysia road money siphoned: Asia Express

Source: https://cointelegraph.com/news/2-6-million-lost-in-nemo-hack-due-to-unaudited-code-and-ignored-vulnerability?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
ChangeX Logo
ChangeX Price(CHANGE)
$0.00141991
$0.00141991$0.00141991
-0.07%
USD
ChangeX (CHANGE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

BullZilla, Shiba Inu, and Goatseus Maximus Take the Spotlight

BullZilla, Shiba Inu, and Goatseus Maximus Take the Spotlight

The post BullZilla, Shiba Inu, and Goatseus Maximus Take the Spotlight appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 20:15 Discover why BullZilla, Shiba Inu, and Goatseus Maximus rank among the best meme coin presales in September 2025. September 2025 has reignited interest in meme coins. While traditional altcoins focus on fundamentals, meme coins thrive on energy, community, and clever narratives. Among the best meme coin presales in September 2025, three stand out for their momentum and market impact: Bull Zilla, Shiba Inu, and Goatseus Maximus. Each offers a unique route for traders and students of finance alike, blending community-driven hype with structured tokenomics. BullZilla continues to command headlines with its presale math and massive ROI potential. Shiba Inu, the veteran of meme mania, still finds ways to reinvent itself. Goatseus Maximus, the fresh arrival, builds on humor and meme storytelling while aiming for short-term gains. Together, they define what meme coin culture looks like heading into Q4 2025. BullZilla: Presale Math Meets Meme Culture BullZilla is not just another viral project. It has crafted a presale model with baked-in returns that investors can map out before listings. The token’s early stages already demonstrate what makes it one of the best meme coin presales in September 2025. BullZilla ROI Table Stage Price ($) ROI Until Listing ($0.00527) $1,000 Investment (Tokens) Value at Listing ($) 3B 0.00006574 7918.57% 15.21M 80,185.73 3C 0.00007241 7169.38% 13.80M 72,703.40 Early Joiners 0.000503 1043.30% 1.99M 20,783.70 This table reflects how even small contributions multiply once BullZilla lists at its projected $0.00527. Unlike meme tokens that rely solely on narrative, BullZilla ($BZIL) merges narrative with math. For anyone who missed Shiba Inu or Dogecoin’s breakout, this structure makes it easy to calculate possible gains. Beyond ROI, the presale’s branding of “Whale Signal Detected” during stage 3rd builds psychological urgency. It cleverly ties meme energy with professional-grade tokenomics. For these reasons,…
Share
BitcoinEthereumNews2025/09/18 03:20
Zoom (ZM) Stock Slides as Investors Fear Anthropic and OpenAI AI Agents

Zoom (ZM) Stock Slides as Investors Fear Anthropic and OpenAI AI Agents

TLDR Zoom (ZM) closed down 5.7% at $79.24, underperforming the S&P 500 which fell just 0.11% The drop was driven by investor fears that AI agents from Anthropic
Share
Coincentral2026/04/11 20:07
WordPress Development Best Practices: Tips for Building High-Performance Websites

WordPress Development Best Practices: Tips for Building High-Performance Websites

Learn WordPress development best practices to build fast, secure, and scalable websites. Discover expert tips, hosting strategies, and optimization techniques.
Share
Techbullion2026/04/11 19:51

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!