The post Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits appeared on BitcoinEthereumNews.com. Sui-based yield trading protocol Nemo lost about $2.59 million due to a known vulnerability introduced by non-audited code being deployed, according to the project. According to Nemo’s post-mortem analysis of the Sept. 7 hack, a flaw in a function intended to reduce slippage allowed the attacker to change the state of the protocol. This function, named “get_sy_amount_in_for_exact_py_out,” was pushed onchain without being audited by smart contract auditor Asymptotic. Furthermore, Asymptotic’s team identified the issue in a preliminary report. Still, the Nemo team admits that its “team did not adequately address this security concern in a timely manner.” Deploying new code only required a signature from a single address, allowing the developer to push unaudited code onchain without disclosing the changes. Furthermore, he did not use the confirmation hash provided in the audit for the deployment, breaking the procedure. This is not the first time a hack was revealed to have been easily preventable. The report follows NFT trading platform SuperRare suffering a $730,000 exploit in late July due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices. Related: Bubblemaps alleges largest Sybil attack in crypto history on MYX airdrop Security procedures changed too late The vulnerable code was pushed onchain in early January. The upgrade procedure, which would likely have prevented the unaudited code from being deployed onchain, was implemented in April. Despite the upgrade, the vulnerability had already made its way into the production environment. Asymptotic warned Nemo of the vulnerability on Aug. 11, but the project said it was focused on other issues and failed to address it before the exploit. Related: Failed NPM exploit highlights looming threat to crypto security: Exec Nemo pauses protocol, prepares patch According to the analysis, Nemo’s protocol core functions are now paused to… The post Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits appeared on BitcoinEthereumNews.com. Sui-based yield trading protocol Nemo lost about $2.59 million due to a known vulnerability introduced by non-audited code being deployed, according to the project. According to Nemo’s post-mortem analysis of the Sept. 7 hack, a flaw in a function intended to reduce slippage allowed the attacker to change the state of the protocol. This function, named “get_sy_amount_in_for_exact_py_out,” was pushed onchain without being audited by smart contract auditor Asymptotic. Furthermore, Asymptotic’s team identified the issue in a preliminary report. Still, the Nemo team admits that its “team did not adequately address this security concern in a timely manner.” Deploying new code only required a signature from a single address, allowing the developer to push unaudited code onchain without disclosing the changes. Furthermore, he did not use the confirmation hash provided in the audit for the deployment, breaking the procedure. This is not the first time a hack was revealed to have been easily preventable. The report follows NFT trading platform SuperRare suffering a $730,000 exploit in late July due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices. Related: Bubblemaps alleges largest Sybil attack in crypto history on MYX airdrop Security procedures changed too late The vulnerable code was pushed onchain in early January. The upgrade procedure, which would likely have prevented the unaudited code from being deployed onchain, was implemented in April. Despite the upgrade, the vulnerability had already made its way into the production environment. Asymptotic warned Nemo of the vulnerability on Aug. 11, but the project said it was focused on other issues and failed to address it before the exploit. Related: Failed NPM exploit highlights looming threat to crypto security: Exec Nemo pauses protocol, prepares patch According to the analysis, Nemo’s protocol core functions are now paused to…

Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits

Sui-based yield trading protocol Nemo lost about $2.59 million due to a known vulnerability introduced by non-audited code being deployed, according to the project.

According to Nemo’s post-mortem analysis of the Sept. 7 hack, a flaw in a function intended to reduce slippage allowed the attacker to change the state of the protocol. This function, named “get_sy_amount_in_for_exact_py_out,” was pushed onchain without being audited by smart contract auditor Asymptotic.

Furthermore, Asymptotic’s team identified the issue in a preliminary report. Still, the Nemo team admits that its “team did not adequately address this security concern in a timely manner.”

Deploying new code only required a signature from a single address, allowing the developer to push unaudited code onchain without disclosing the changes. Furthermore, he did not use the confirmation hash provided in the audit for the deployment, breaking the procedure.

This is not the first time a hack was revealed to have been easily preventable. The report follows NFT trading platform SuperRare suffering a $730,000 exploit in late July due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices.

Related: Bubblemaps alleges largest Sybil attack in crypto history on MYX airdrop

Security procedures changed too late

The vulnerable code was pushed onchain in early January. The upgrade procedure, which would likely have prevented the unaudited code from being deployed onchain, was implemented in April.

Despite the upgrade, the vulnerability had already made its way into the production environment. Asymptotic warned Nemo of the vulnerability on Aug. 11, but the project said it was focused on other issues and failed to address it before the exploit.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Nemo pauses protocol, prepares patch

According to the analysis, Nemo’s protocol core functions are now paused to prevent further losses. The team is collaborating with multiple security teams and providing all relevant addresses to assist in freezing assets on centralized exchanges.

A patch has now been developed, and Asymptotic is auditing the new code. The project said it removed its flash loan function, fixed the vulnerable code and added a manual-reset feature to restore affected values. Nemo is also designing a compensation plan for users, including debt structuring at the tokenomics level.

Nemo apologized to its users and claims to have learned that “security and risk management demand constant vigilance.” The team also promised to improve its defences and apply stricter protocol control.

Magazine: North Korea crypto hackers tap ChatGPT, Malaysia road money siphoned: Asia Express

Source: https://cointelegraph.com/news/2-6-million-lost-in-nemo-hack-due-to-unaudited-code-and-ignored-vulnerability?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
ChangeX Logo
ChangeX Price(CHANGE)
$0.00030888
$0.00030888$0.00030888
0.00%
USD
ChangeX (CHANGE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
Explosive 25% Penalty On Nations Trading With Tehran

Explosive 25% Penalty On Nations Trading With Tehran

The post Explosive 25% Penalty On Nations Trading With Tehran appeared on BitcoinEthereumNews.com. Trump Iran Tariffs: Explosive 25% Penalty On Nations Trading
Share
BitcoinEthereumNews2026/02/07 08:10