Sui-based yield trading protocol Nemo has lost approximately $2.59 million due to a previously identified vulnerability in unaudited code. The project's team has admitted to not adequately addressing the security concern in a timely manner, leading to the exploit.
Nemo Security Incident: Cause, Process, and Fund Tracing Report V1.1
Key Takeaways
-
Nemo lost $2.59 million in a hack exploiting unaudited code.
-
An auditor, Asymptotic, had previously flagged the vulnerability.
-
The project team failed to address the security concern promptly.
-
Code deployment procedures were lax, allowing unaudited code to be pushed.
-
Security upgrade procedures were implemented after the vulnerable code was deployed.
The Vulnerability and Its Exploitation
The hack occurred on September 7th, exploiting a flaw in a function designed to reduce slippage. This function, named “get_sy_amount_in_for_exact_py_out,” was deployed on-chain without a full audit by smart contract auditor Asymptotic. The Nemo team acknowledged that they "did not adequately address this security concern in a timely manner."
Lax Security Procedures
Further compounding the issue, the deployment of new code only required a single signature, enabling the developer to push unaudited changes without disclosure. The developer also failed to use the confirmation hash provided in the audit for deployment, deviating from established procedures. This incident follows a pattern seen in other DeFi exploits, such as the $730,000 exploit on NFT trading platform SuperRare, which was attributed to a basic smart contract bug preventable with standard testing.
The vulnerable code was initially deployed in January, while the upgrade procedure that could have prevented such an incident was only implemented in April. Despite this upgrade, the vulnerability had already been integrated into the production environment. Asymptotic had issued a warning about the vulnerability on August 11th, but Nemo's team was reportedly focused on other issues and failed to act before the exploit.
Nemo's Response and Future Plans
In response to the hack, Nemo has paused its protocol's core functions to prevent further losses. The team is actively working with multiple security firms and providing information to aid in freezing assets on centralized exchanges. A patch has been developed, and Asymptotic is currently auditing the new code. The project has removed its flash loan function, fixed the vulnerable code, and introduced a manual-reset feature to rectify affected values. Nemo is also developing a compensation plan for affected users, which includes debt structuring at the tokenomics level.
The Nemo team has apologized to its users, stating they have learned the importance of "constant vigilance" in security and risk management. They have pledged to enhance their security measures and implement stricter protocol controls.
Sources
-
Auditor Flagged Issue Before $2.59M Nemo Hack, Team Admits, Cointelegraph.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
