Nemo Protocol Suffers $2.6M Hack Due to Unaudited Code Deployment
DeFi platform Nemo Protocol, operating on the sui blockchain, lost $2.6 million in a September exploit traced to unaudited code deployed to mainnet. A developer introduced unvetted features—including a mistakenly public flash loan function and a vulnerable query function—after MoveBit's initial audit. The flaws were pushed live via a single-signature upgrade system, bypassing security checks.
Governance failures compounded the risk. Despite migrating to multi-signature controls in April and receiving August warnings from Asymptotic about state-modification vulnerabilities, the team prioritized product development over fixes. Attackers weaponized these oversights on September 7, draining funds through the exposed functions.