The post Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits appeared on BitcoinEthereumNews.com. Sui-based yield trading protocol Nemo lost about $2.59 million due to a known vulnerability introduced by non-audited code being deployed, according to the project. According to Nemo’s post-mortem analysis of the Sept. 7 hack, a flaw in a function intended to reduce slippage allowed the attacker to change the state of the protocol. This function, named “get_sy_amount_in_for_exact_py_out,” was pushed onchain without being audited by smart contract auditor Asymptotic. Furthermore, Asymptotic’s team identified the issue in a preliminary report. Still, the Nemo team admits that its “team did not adequately address this security concern in a timely manner.” Deploying new code only required a signature from a single address, allowing the developer to push unaudited code onchain without disclosing the changes. Furthermore, he did not use the confirmation hash provided in the audit for the deployment, breaking the procedure. This is not the first time a hack was revealed to have been easily preventable. The report follows NFT trading platform SuperRare suffering a $730,000 exploit in late July due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices. Related: Bubblemaps alleges largest Sybil attack in crypto history on MYX airdrop Security procedures changed too late The vulnerable code was pushed onchain in early January. The upgrade procedure, which would likely have prevented the unaudited code from being deployed onchain, was implemented in April. Despite the upgrade, the vulnerability had already made its way into the production environment. Asymptotic warned Nemo of the vulnerability on Aug. 11, but the project said it was focused on other issues and failed to address it before the exploit. Related: Failed NPM exploit highlights looming threat to crypto security: Exec Nemo pauses protocol, prepares patch According to the analysis, Nemo’s protocol core functions are now paused to… The post Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits appeared on BitcoinEthereumNews.com. Sui-based yield trading protocol Nemo lost about $2.59 million due to a known vulnerability introduced by non-audited code being deployed, according to the project. According to Nemo’s post-mortem analysis of the Sept. 7 hack, a flaw in a function intended to reduce slippage allowed the attacker to change the state of the protocol. This function, named “get_sy_amount_in_for_exact_py_out,” was pushed onchain without being audited by smart contract auditor Asymptotic. Furthermore, Asymptotic’s team identified the issue in a preliminary report. Still, the Nemo team admits that its “team did not adequately address this security concern in a timely manner.” Deploying new code only required a signature from a single address, allowing the developer to push unaudited code onchain without disclosing the changes. Furthermore, he did not use the confirmation hash provided in the audit for the deployment, breaking the procedure. This is not the first time a hack was revealed to have been easily preventable. The report follows NFT trading platform SuperRare suffering a $730,000 exploit in late July due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices. Related: Bubblemaps alleges largest Sybil attack in crypto history on MYX airdrop Security procedures changed too late The vulnerable code was pushed onchain in early January. The upgrade procedure, which would likely have prevented the unaudited code from being deployed onchain, was implemented in April. Despite the upgrade, the vulnerability had already made its way into the production environment. Asymptotic warned Nemo of the vulnerability on Aug. 11, but the project said it was focused on other issues and failed to address it before the exploit. Related: Failed NPM exploit highlights looming threat to crypto security: Exec Nemo pauses protocol, prepares patch According to the analysis, Nemo’s protocol core functions are now paused to…

Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits

Sui-based yield trading protocol Nemo lost about $2.59 million due to a known vulnerability introduced by non-audited code being deployed, according to the project.

According to Nemo’s post-mortem analysis of the Sept. 7 hack, a flaw in a function intended to reduce slippage allowed the attacker to change the state of the protocol. This function, named “get_sy_amount_in_for_exact_py_out,” was pushed onchain without being audited by smart contract auditor Asymptotic.

Furthermore, Asymptotic’s team identified the issue in a preliminary report. Still, the Nemo team admits that its “team did not adequately address this security concern in a timely manner.”

Deploying new code only required a signature from a single address, allowing the developer to push unaudited code onchain without disclosing the changes. Furthermore, he did not use the confirmation hash provided in the audit for the deployment, breaking the procedure.

This is not the first time a hack was revealed to have been easily preventable. The report follows NFT trading platform SuperRare suffering a $730,000 exploit in late July due to a basic smart contract bug that experts say could have easily been prevented with standard testing practices.

Related: Bubblemaps alleges largest Sybil attack in crypto history on MYX airdrop

Security procedures changed too late

The vulnerable code was pushed onchain in early January. The upgrade procedure, which would likely have prevented the unaudited code from being deployed onchain, was implemented in April.

Despite the upgrade, the vulnerability had already made its way into the production environment. Asymptotic warned Nemo of the vulnerability on Aug. 11, but the project said it was focused on other issues and failed to address it before the exploit.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Nemo pauses protocol, prepares patch

According to the analysis, Nemo’s protocol core functions are now paused to prevent further losses. The team is collaborating with multiple security teams and providing all relevant addresses to assist in freezing assets on centralized exchanges.

A patch has now been developed, and Asymptotic is auditing the new code. The project said it removed its flash loan function, fixed the vulnerable code and added a manual-reset feature to restore affected values. Nemo is also designing a compensation plan for users, including debt structuring at the tokenomics level.

Nemo apologized to its users and claims to have learned that “security and risk management demand constant vigilance.” The team also promised to improve its defences and apply stricter protocol control.

Magazine: North Korea crypto hackers tap ChatGPT, Malaysia road money siphoned: Asia Express

Source: https://cointelegraph.com/news/2-6-million-lost-in-nemo-hack-due-to-unaudited-code-and-ignored-vulnerability?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
ChangeX Logo
ChangeX Price(CHANGE)
$0.00030888
$0.00030888$0.00030888
0.00%
USD
ChangeX (CHANGE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Cashing In On University Patents Means Giving Up On Our Innovation Future

Cashing In On University Patents Means Giving Up On Our Innovation Future

The post Cashing In On University Patents Means Giving Up On Our Innovation Future appeared on BitcoinEthereumNews.com. “It’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress,” writes Pipes. Getty Images Washington is addicted to taxing success. Now, Commerce Secretary Howard Lutnick is floating a plan to skim half the patent earnings from inventions developed at universities with federal funding. It’s being sold as a way to shore up programs like Social Security. In reality, it’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress. Yes, taxpayer dollars support early-stage research. But the real payoff comes later—in the jobs created, cures discovered, and industries launched when universities and private industry turn those discoveries into real products. By comparison, the sums at stake in patent licensing are trivial. Universities collectively earn only about $3.6 billion annually in patent income—less than the federal government spends on Social Security in a single day. Even confiscating half would barely register against a $6 trillion federal budget. And yet the damage from such a policy would be anything but trivial. The true return on taxpayer investment isn’t in licensing checks sent to Washington, but in the downstream economic activity that federally supported research unleashes. Thanks to the bipartisan Bayh-Dole Act of 1980, universities and private industry have powerful incentives to translate early-stage discoveries into real-world products. Before Bayh-Dole, the government hoarded patents from federally funded research, and fewer than 5% were ever licensed. Once universities could own and license their own inventions, innovation exploded. The result has been one of the best returns on investment in government history. Since 1996, university research has added nearly $2 trillion to U.S. industrial output, supported 6.5 million jobs, and launched more than 19,000 startups. Those companies pay…
Share
BitcoinEthereumNews2025/09/18 03:26
Silver Price Crash Is Over “For Real This Time,” Analyst Predicts a Surge Back Above $90

Silver Price Crash Is Over “For Real This Time,” Analyst Predicts a Surge Back Above $90

Silver has been taking a beating lately, and the Silver price hasn’t exactly been acting like a safe haven. After running up into the highs, the whole move reversed
Share
Captainaltcoin2026/02/07 03:15
Citi Caps Year-End at $4,300, But ETF outflows Challenge Outlook

Citi Caps Year-End at $4,300, But ETF outflows Challenge Outlook

The post Citi Caps Year-End at $4,300, But ETF outflows Challenge Outlook appeared on BitcoinEthereumNews.com. Ethereum Price Prediction: Citi Caps Year-End at $4,300, But ETF outflows Challenge Outlook Disclaimer: The information found on NewsBTC is for educational purposes only. It does not represent the opinions of NewsBTC on whether to buy, sell or hold any investments and naturally investing carries risks. You are advised to conduct your own research before making any investment decisions. Use information provided on this website entirely at your own risk. Related News © 2025 NewsBTC. All Rights Reserved. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://www.newsbtc.com/news/ethereum/ethereum-price-prediction-citi-caps-year-end-at-4300-but-etf-outflows-challenge-outlook/
Share
BitcoinEthereumNews2025/09/18 14:30