Crypto2Community
HomeCrypto NewsReviewsGuidesGamblingTradingPress Release

Crypto 2 Community

  • About Us
  • Editorial Policy
  • Why Trust Us
  • Contact Us
  • Privacy Policy
  • Submit a Press Release

Cryptocurrency

  • Best Cryptos to Buy Now
  • Best Crypto Exchanges
  • How To Buy Cryptocurrency
  • Best Crypto Wallets
  • Best Altcoins to Buy

Gambling

  • Best Bitcoin Casinos
  • Best Ethereum Casinos
  • Best Crypto Live Casinos
  • Best Crypto Faucet Casinos
  • Provably Fair Bitcoin Casinos

Best Platforms

  • eToro Review
  • BC.Game Review
  • Jackbit Review
  • Metaspins Review
  • CryptoLeo Review

© 2026 Crypto2Community.com

CAUTION: The content presented on this platform is not intended as financial guidance, and we lack the authorization to offer investment advice. Any material found on this website should not be construed as an endorsement or recommendation of any specific trading strategy or investment decision. The information provided herein is of a general nature, and therefore it is essential to evaluate it in the context of your objectives, financial circumstances, and requirements.

Investment activities involve speculation and entail inherent risks to your capital. This website is not intended for utilization in jurisdictions where the described trading or investment activities are prohibited, and it should only be accessed by individuals who are legally permitted to do so. Depending on your country or state of residence, your investment may not be eligible for investor protection, hence it is advisable to conduct thorough research independently or seek appropriate guidance. While this website is accessible to you free of charge, please note that we may receive commissions from the companies featured on this site.

Disclosure: 18+ Rules regarding online gambling vary from country to country, please ensure you are following them and gamble responsibly. The content on this website is provided for entertainment purposes only. We may utilise affiliate links within our content, and receive commission.

Home/Crypto News
Crypto News

Nemo Protocol Loses $2.6M After Developer Deploys Unaudited Smart Contract

Author
Raymond Munene
Raymond Munene
Crypto Writer
Fact Checked by Joshua Downes
Last updated: September 11, 2025
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
TweetShareLinkedIn0
Nemo Protocol Loses $2.6M After Developer Deploys Unaudited Smart Contract

Highlights:

  • A single developer deployed unaudited code that enabled the $2.6M exploit on Nemo Protocol.
  • The flash loan and query vulnerabilities were introduced after the audit.
  • The funds were bridged to Ethereum, with $2.4M still in a hacker’s wallet.

On Sept. 8, attackers exploited two smart contract flaws in Nemo Protocol, draining $2.6 million from the funds of users. According to the post-mortem report, the cause of the incident was due to an unaudited rogue developer injecting unaudited features into the mainnet codebase. These features included a flash loan function mistakenly set as public and a query method with the ability to perform unauthorized state changes.

The vulnerabilities gave hackers the ability to mint additional SY tokens and manipulate pool prices, ultimately draining liquidity. Within minutes, the attackers were able to bridge assets stolen from the Sui network to Ethereum using Wormhole’s CCTP bridge. Around $2.4 million is still held in one Ethereum wallet associated with the exploit.

As many of you know, Nemo Protocol suffered a security incident on Sept 8. Today we are releasing our full incident report to provide transparency into our response, including the root cause, learnings, and next steps. We sincerely apologize for the impact on @Movebit and for the… pic.twitter.com/ROml1aUNUv

— Nemo (@nemoprotocol) September 11, 2025

Governance Gaps and Unapproved Code in Nemo Protocol

The root of the incident goes back to January 2025. After receiving an initial audit from MoveBit, a developer merged previously audited fixes with new and unverified features. These new elements, however, were never disclosed through the audit process. The developer deployed the modified version with a single-signature address, a governance structure without safeguards for internal approval.

By skipping the peer review process, the developer contributed live vulnerabilities to the mainnet of the Nemo Protocol. This unauthorized contract continued to exist despite the project’s transition to a multi-signature upgrade model in April. Moreover, internal monitoring failed to detect the differences between the audited and deployed versions of the code.

Further warnings came in August when a related flaw was flagged by security firm Asymptotic. Despite the available support, the developer ignored the alert and did not make any changes. This failure to act contributed directly to the successful conduct of the attack of September.

Exploit Execution, Response, and Recovery

The exploit commenced at 16:00 UTC on September 8. Attackers used the exposed flash loan function in conjunction with the faulty method of the query to manipulate the contract behavior. These changes consequently enabled the generation of false yield situations and enabled excessive token minting. Arbitrageurs drained the SY/PT pool still further before the team froze core functions.

#PeckShieldAlert @nemoprotocol on @SuiNetwork has been exploited for $2.4M

The hacker bridged $USDC via Circle from Arbitrum to Ethereum. pic.twitter.com/QSB0ec7TZy

— PeckShieldAlert (@PeckShieldAlert) September 8, 2025

Unusual returns in YT pools of more than 30x alerted the Nemo team within 30 minutes. Immediate action followed, including halting protocol operations, patching the code and launching emergency audits. The team also contacted centralized exchanges to aid in the tracing and potential freezing of stolen assets.

To compensate for user losses, Nemo Protocol is working on a compensation plan to structure debt. It includes tokenomic adjustments that will be shared with the community prior to release. Meanwhile, monitoring systems have been upgraded, while security partnerships have been expanded across the Sui ecosystem.

The team stressed that future upgrades will only go through multi-signature wallets and audit checkpoints will be more rigorous. In addition, a white-hat bounty program has been implemented to aid further recovery and decrease risks in the future.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Tags

Crypto HacksNemo ProtocolSmart Contractssui
Raymond Munene
Author

Raymond Munene

Raymond Munene is a crypto content writer who contributes to Crypto2Community. With over three years of experience, he is interested in Bitcoin, Blockchain, and Technical Analysis. Focusing on daily market analysis, his research helps traders and investors alike. His particular interest in cryptocurrency and blockchain aids his audience.

View full profile ›

ℹ️About Crypto2Community's Editorial Process

Crypto2Community's editorial policy is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict editorial policy and sourcing standards, and each page undergoes diligent review by our team of top crypto industry experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

More by this author:

  • Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
  • CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
  • Circle Explains USDC Freeze Limits After Drift Protocol Hack

Related Articles:

Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
Crypto News11 hours ago
Syed Ali Haider
By Syed Ali Haider4/11/2026
CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
Crypto News12 hours ago
Syed Ali Haider
By Syed Ali Haider4/11/2026
Circle Explains USDC Freeze Limits After Drift Protocol Hack
Circle Explains USDC Freeze Limits After Drift Protocol Hack
Crypto News1 days ago
Chinedu Agbakwusi
By Chinedu Agbakwusi4/10/2026

Popular Topics

  • Sei Price Prediction 2025, 2030, 2040
  • Uniswap Price Prediction 2025, 2030, 2040
  • Near Protocol Price Prediction 2025, 2030, 2040
  • Loopring Price Prediction 2025, 2030, 2040
  • Chainlink Price Prediction 2025, 2030, 2040

Trending News

  • Bitwise Files Second Amendment for Hyperliquid ETF, HYPE Price Climbs
  • CFTC Appoints Innovation Task Force Team to Oversee Crypto and AI Developments
  • Circle Explains USDC Freeze Limits After Drift Protocol Hack
  • Aethir Halts Bridge Exploit, Caps Losses Below $90K
  • Ethereum Network Activity Hits All-Time High with 1.3M Transactions
  • Hong Kong Issues First Stablecoin Licences to HSBC and Standard Chartered Venture
  • Bitcoin Could Be Quantum Safe Without a Soft Fork, Analyst Says
  • Top Crypto Picks for Today, April 10 – Zcash, Hyperliquid, BNB
  • Japan Approves Bill to Treat Crypto as Financial Instruments
  • Coinbase CEO Backs Treasury Secretary’s Call to Pass the CLARITY Act
  • Hyperliquid Price Outlook – HYPE Gains Strength, $42.15 in Focus
  • Bitmine Uplists to NYSE with 4.8M ETH and a $4 Billion Buyback
  • Best Crypto Gainers Today, April 9 – SIREN, DEXE, JUST
  • Bitcoin Price Holds Near $71K as Iran BTC Toll Plan Raises Uncertainty
  • Bitcoin Depot Loses 50.9 BTC in Wallet Breach Revealed in SEC Filing
  • Ethereum Foundation Offloads 3,750 ETH Worth $8.3M
  • Stablecoin Volumes May Hit $1.5 Quadrillion by 2035: Chainalysis
  • Treasury Secretary Scott Bessent Calls CLARITY Act a National Priority
  • Canary Capital Seeks SEC Approval for Spot PEPE ETF
  • Iran Plans Bitcoin Toll for Laden Oil Tankers Crossing Strait of Hormuz