Nemo Protocol Explains $2.6 Million Exploit Caused by Code Vulnerabilities

2025/09/11 18:05

TLDR

  • Nemo Protocol’s $2.6 million exploit stemmed from unaudited code and developer errors.
  • The vulnerabilities were introduced in January and led to unauthorized access and fund theft.
  • Nemo has paused operations, patched the issues, and is working on compensating affected users.
  • The attack exploited a flash loan function and query flaw, draining assets from liquidity pools.

Nemo Protocol, a DeFi platform built on the Sui blockchain, has outlined the causes of its $2.6 million exploit earlier this month. The platform revealed in a post-mortem report that the attack was due to two vulnerabilities introduced into its code by a developer and deployed without proper auditing. The breach, which occurred on September 7, exploited flaws that allowed unauthorized access and manipulation of its smart contract.

Vulnerabilities in the Codebase

The Nemo team explained that the exploit stemmed from two primary issues within the code. First, an internal flash loan function was accidentally exposed to the public. Second, a flaw in a query function enabled unauthorized state changes within the contract. These vulnerabilities were introduced in January 2023, after the protocol received an initial audit report from blockchain security firm MoveBit. Despite the warnings, one of Nemo’s developers incorporated new, unaudited features into the codebase and deployed them to the mainnet.

Notably, the governance structure of the protocol relied on a single-signature address for upgrades, which allowed the unvetted code to be deployed. The team acknowledged that this system failed to prevent risky updates from being introduced. Furthermore, despite a security warning from Asymptotic in August regarding a separate vulnerability, the team did not take immediate action to address the issue.

Exploit Mechanics and Fund Movement

The attacker exploited the combination of the flash loan function and the query function vulnerability to manipulate the contract’s internal state. This enabled the unauthorized draining of assets from the SY/PT liquidity pool. The stolen funds were moved from the Sui network to Ethereum via the Wormhole CCTP bridge. As of now, the majority of the stolen assets remain in a single address.

In response to the breach, Nemo Protocol has paused its core functions to prevent further damage. The team has already patched the vulnerabilities and submitted the updated code for an emergency audit. They are working closely with security teams on the Sui blockchain to trace the stolen funds. Furthermore, the team is planning to compensate affected users.

Acknowledging the Failures

Despite multiple audits and safety measures, Nemo acknowledged that it had relied too heavily on past assurances without maintaining rigorous scrutiny at every step. The report stated that the team’s failure to catch these vulnerabilities during the development phase contributed to the exploit.

Nemo Protocol, a yield infrastructure platform, focuses on yield tokenization and aims to improve DeFi interactions. This breach has raised concerns about the platform’s code integrity, but the team is taking steps to address the issues and prevent future attacks.

The post Nemo Protocol Explains $2.6 Million Exploit Caused by Code Vulnerabilities appeared first on CoinCentral.

Məsuliyyətdən İmtina: Bu saytda yenidən yayımlanan məqalələr ictimai platformalardan götürülmüşdür və yalnız məlumat xarakteri daşıyır. MEXC-in baxışlarını əks etdirməyə bilər. Bütün hüquqlar orijinal müəlliflərə məxsusdur. Hər hansı bir məzmunun üçüncü tərəfin hüquqlarını pozduğunu düşünürsünüzsə, zəhmət olmasa, service@support.mexc.com ilə əlaqə saxlayaraq silinməsini tələb edin. MEXC məzmunun dəqiqliyinə, tamlığına və ya vaxtında yenilənməsinə dair heç bir zəmanət vermir və təqdim olunan məlumatlar əsasında görülən hərəkətlərə görə məsuliyyət daşımır. Məzmun maliyyə, hüquqi və ya digər peşəkar məsləhət xarakteri daşımır və MEXC tərəfindən tövsiyə və ya təsdiq kimi qəbul edilməməlidir.
Məqaləni Paylaşın

Bunları da Bəyənə Bilərsiniz

America Allegedly Plans to Use Digital Currency to Erase $37 Trillion — BRICS Called an Emergency…

America Allegedly Plans to Use Digital Currency to Erase $37 Trillion — BRICS Called an Emergency…

Russian officials claim the US is orchestrating a massive financial reset through stablecoins, prompting desperate countermeasures from…Continue reading on Coinmonks »
Paylaşın
Medium2025/09/11 20:42
Paylaşın
DeLorean Embraces Web3 with $DMC Token's Regulatory Approval in Europe

DeLorean Embraces Web3 with $DMC Token's Regulatory Approval in Europe

A New Era for DeLorean in the Digital Asset Landscape On September 11, 2025, in a significant development from Madrid, Spain, DeLorean Labs announced the successful integration of its $DMC token within the stringent regulatory frameworks of the European Union. The European Securities and Markets Authority (ESMA) and Spain’s National Securities Market Commission (CNMV) have acknowledged the $DMC token as compliant with the Markets in Crypto-Assets Regulation (MiCA). The Implications of MiCA's Adoption for DeLorean By aligning with MiCA, DeLorean Labs not only pioneers as one of the first recognized consumer brands under this new regulation but also paves the way for future growth across European borders. MiCA, representing the EU's unified regulatory framework for crypto-assets, harmonizes the standards across all 27 Member States and offers a robust consumer protection mechanism, eliminating the hassle of obtaining multiple national approvals. Advantages of $DMC Token's Classification Under MiCA The official classification of $DMC as a utility token marks it clearly as a non-financial instrument, which distinguishes DeLorean's operations within the legal boundaries of MiCA's Title II provisions. This classification enhances transparency, ensuring that DeLorean's offerings align with Europe's consumer protection and transparency standards. Strategic Growth and Integration in the Web3 Space According to Evan Kuhn, President of DeLorean Labs, achieving MiCA compliance is crucial for the brand's future initiatives. "$DMC supports our vision to integrate fans, gamers, and communities into a digital ecosystem that spans across Europe," he stated. This compliance allows DeLorean to innovate within the Web3 arena, offering enriched digital and real-world interactions. 2025 marked a transformative year for DeLorean Labs with several key developments: Introduction of the $DMC token. Launch of the Reservation Marketplace. Establishment of significant blockchain and cultural partnerships. These advancements, coupled with the MiCA compliance, signify DeLorean's transition into a comprehensive lifestyle ecosystem powered by Web3 technologies. Looking forward, DeLorean Labs plans to expand its reach beyond Europe, with strategic plans in the U.S. and Asia. This global perspective is supported by ongoing partnerships and cultural initiatives aimed at solidifying DeLorean’s presence in the Web3 market. For press inquiries, contact: Jacob Galland jake@lunapr.io Disclaimer: This is a sponsored article and is for informational purposes only. It does not reflect the views of Bitzo, nor is it intended to be used as legal, tax, investment, or financial advice.
Paylaşın
Coinstats2025/09/11 20:17
Paylaşın