Close Menu
    What's Hot

    Kyivstar Group jumps after posting double-digit revenue growth

    March 13, 2026

    Layoff Announcement Memos Are Reading More Like AI-Era Manifestos

    March 13, 2026

    BlackRock Launches Staked Ethereum Trust With 82% Rewards

    March 13, 2026
    Facebook X (Twitter) Instagram
    Hot Paths
    • Home
    • News
    • Politics
    • Money
    • Personal Finance
    • Business
    • Economy
    • Investing
    • Markets
      • Stocks
      • Futures & Commodities
      • Crypto
      • Forex
    • Technology
    Facebook X (Twitter) Instagram
    Hot Paths
    Home»Markets»Crypto»Nemo Protocol Blames $2.6M Exploit on Developer Who Deployed Unaudited Code
    Crypto

    Nemo Protocol Blames $2.6M Exploit on Developer Who Deployed Unaudited Code

    Press RoomBy Press RoomSeptember 11, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Nemo Protocol released a comprehensive post-mortem blaming a rogue developer for deploying unaudited code containing critical vulnerabilities that enabled a $2.59 million exploit on September 7.

    The DeFi yield platform detailed how the unnamed developer secretly introduced new features without audit approval and used unauthorized smart contract versions.

    The attack exploited two key vulnerabilities: a flash loan function incorrectly exposed as public and a query function that could modify contract state without authorization.

    Hackers bridged stolen funds to Ethereum via Wormhole CCTP, with $2.4 million currently held in the hacker’s address.

    As many of you know, Nemo Protocol suffered a security incident on Sept 8. Today we are releasing our full incident report to provide transparency into our response, including the root cause, learnings, and next steps. We sincerely apologize for the impact on @Movebit and for the… pic.twitter.com/ROml1aUNUv

    — Nemo (@nemoprotocol) September 11, 2025

    How it All Started

    The root cause traces to January 2025, when a developer submitted code containing unaudited features to MoveBit auditors.

    The developer failed to highlight new additions while mixing previously audited fixes with unreviewed functionality.

    MoveBit issued its final audit report based on incomplete information. The same developer then deployed contract version 0xcf34 using single-signature address 0xf55c rather than the audit-confirmed hash, bypassing internal review processes.

    Asymptotic team identified the critical C-2 vulnerability in August, warning that some functions could modify code without permission.

    The developer dismissed the severity and failed to implement necessary fixes despite available support.

    Attack execution began at 16:00 UTC on September 7 with hackers leveraging the flash loan function and the get_sy_amount_in_for_exact_py_out query vulnerability.

    The team detected anomalies thirty minutes later when YT yields displayed over 30x returns.

    On August 11, we reported a Critical vulnerability (C-2) to Nemo regarding unauthorized manipulation of py_index_stored, an index variable which affects all interest, yield, and conversion calculations. We warned of potential "incorrect payouts, market disruption, and loss of… https://t.co/RCgiloT7fE

    — Asymptotic (@AsymptoticTech) September 11, 2025

    The Developer’s Secret Code Deployment

    In late 2024, initial audit submissions correctly configured flash_loan as an internal non-callable function while development teams iterated on features.

    The developer drew inspiration from Aave and Uniswap protocols to maximize composability through flash loan capabilities.

    However, the implementation critically underestimated security risks and incorrectly used public methods rather than internal functions.

    The earlier-mentioned function, intended to enhance swap quoting mechanisms, contained implementation errors.

    Functions designed for read-only purposes were coded with write capabilities, creating the primary attack vector.

    On January 5, 2025, the developer integrated unaudited features into the final codebase after receiving MoveBit’s initial audit report.

    The mixed version contained both fixed issues and new unaudited features without explicit scope highlighting.

    The developer communicated directly with the MoveBit team on January 6, obtaining final audit reports through modification of previous versions.

    Instead of using confirmation hashes from audit reports, separate upgrades and deployments occurred without the internal team’s knowledge.

    Single-signature deployment address enabled unauthorized contract version activation. This version remained in the active code until exploit occurrence despite subsequent security procedure implementations.

    April’s transition to multi-signature upgrade protocols failed to address the fundamental issue.

    The developer transferred only contract caps while maintaining vulnerable code rather than deploying audit-confirmed versions.

    Nemo Protocol loses $2.4M to hackers on Sui blockchain as TVL crashes 75% from $6.3M, marking the third major DeFi hack this month alone.#Sui #Nemohttps://t.co/ZrVfJk2cZr

    — Cryptonews.com (@cryptonews) September 8, 2025

    Fund Recovery and Security Remediation Efforts

    Stolen assets totaling $2.59 million were quickly moved through sophisticated laundering operations.

    Primary attacker wallet initiated cross-chain transfers at 16:10 UTC via Wormhole CCTP before final aggregation on Ethereum.

    However, security teams established monitoring protocols for the holding address while coordinating with centralized exchanges on asset freezing.

    White-hat agreement frameworks and hacker bounty programs were also implemented to encourage fund recovery.

    As for the remediation effort, emergency incremental audits were submitted to Asymptotic with plans for additional independent security firm reviews.

    Manual-fix functions were also integrated into new contract patches to enable multi-signature wallet restoration of corrupted code.

    As a result of the hack, the total value locked instantly collapsed from $6.3 million to $1.63 million now as users withdrew over $3.8 million worth of USDC and SUI tokens.

    Nemo Protocol Blames $2.6M Exploit on Developer Who Deployed Unaudited Code
    Source: DefiLlama

    To compensate affected users, plans have been put in place for debt-structuring design at the tokenomics level, with community sharing scheduled upon finalization.

    The protocol apologized for security failures while implementing enhanced monitoring, stricter controls, additional audit checkpoints, and expanded bug bounty programs.

    The exploit contributes to the ongoing 2025’s devastating DeFi security crisis with over $2.37 billion in losses across 121 incidents in the first half alone.

    So far this year, September emerged as particularly destructive with SwissBorg’s $41.5 million SOL hack, npm supply chain attacks affecting billions of downloads, and multiple protocol exploits happening almost at the same time.

    The post Nemo Protocol Blames $2.6M Exploit on Developer Who Deployed Unaudited Code appeared first on Cryptonews.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Press Room

    Related Posts

    BlackRock Launches Staked Ethereum Trust With 82% Rewards

    March 13, 2026

    AAVE Crypto Swap Costs $50M as ETH MEV Pocketed $9.9M

    March 13, 2026

    Quantum Computers Could Break Bitcoin Wallets by 2030

    March 13, 2026
    Leave A Reply Cancel Reply

    LATEST NEWS

    Kyivstar Group jumps after posting double-digit revenue growth

    March 13, 2026

    Layoff Announcement Memos Are Reading More Like AI-Era Manifestos

    March 13, 2026

    BlackRock Launches Staked Ethereum Trust With 82% Rewards

    March 13, 2026

    Elon Musk Says XAI Missed Good Talent — so He’s Reopening the Books

    March 13, 2026
    POPULAR
    Business

    The Business of Formula One

    May 27, 2023
    Business

    Weddings and divorce: the scourge of investment returns

    May 27, 2023
    Business

    How F1 found a secret fuel to accelerate media rights growth

    May 27, 2023
    Advertisement
    Load WordPress Sites in as fast as 37ms!

    Archives

    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • May 2023

    Categories

    • Business
    • Crypto
    • Economy
    • Forex
    • Futures & Commodities
    • Investing
    • Market Data
    • Money
    • News
    • Personal Finance
    • Politics
    • Stocks
    • Technology

    Your source for the serious news. This demo is crafted specifically to exhibit the use of the theme as a news site. Visit our main page for more demos.

    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.