T
iTokenly

Nemo Protocol hack — September 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedSeptember 8, 2025
Target typeOther
Loss$2,590,000Published estimates range $2,400,000 to $2,600,000Price at time of incident
MethodContract logic errorTwo defects in code deployed after the protocol's audit. A flash-loan function was left publicly callable when it should have been restricted, and a function intended only to read pricing data could in fact modify contract state. Chained together they let the attacker borrow, swap and mint in a sequence that distorted the protocol's internal price, minted excess SY tokens and emptied the SY/PT pool. Upgrades were controlled by a single-signature address at the time the vulnerable code went live.
ChainsSui, Ethereum
Audited beforehandMoveBit audited the protocol in January 2025, but the exploited code was deployed afterwards without being submitted for review. Asymptotic flagged related risks in August 2025 and was later engaged for an emergency audit.
OutcomeUnresolved

What happened

Nemo Protocol, a yield-tokenisation and trading platform on Sui, was drained on 7 September 2025, with the incident reported publicly the following day. PeckShield flagged it and put the amount taken at about $2.4 million in USDC, which the attacker bridged out of Sui to Ethereum using Wormhole's CCTP route. Nemo's own post-mortem, published on 10 September, gave total losses of $2.59 million, of which roughly $2.4 million left the protocol and remained in a single attacker-controlled wallet. Total value locked fell from over $6 million to about $1.53 million.

The team attributed the failure to code that never went through review. After MoveBit audited the protocol in January 2025, a developer deployed new features without submitting them for audit and, according to Nemo, did not tell the auditors that new code had been mixed in with the approved fixes. Two defects resulted: a flash-loan function mistakenly left public instead of private, and a function intended only to read pricing data that could in fact change internal contract state. Combined, they let the attacker borrow, swap and mint in a sequence that distorted the internal price, minted excess SY tokens and emptied the SY/PT pool. Upgrades were controlled by a single-signature address when the vulnerable code went live; multi-signature controls were added in April 2025, after the fact. Nemo also said the auditor Asymptotic raised state-modification risks in August 2025 and the issue went unresolved amid shifting priorities.

Nemo paused the protocol after spotting unusual yield jumps, removed the flash-loan function and locked the query method to read-only. It later issued NEOM debt tokens matching users' dollar losses rather than cash, stating that while it would have preferred to reimburse everyone directly in USD, it did not have sufficient funds or capital raised to do so. Holders could exit immediately through an AMM pool paired with USDC or hold the tokens pending fund recovery.

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. crypto.newsSecondary · retrieved 2026-08-01
  3. The Crypto TimesSecondary · retrieved 2026-08-01
  4. The BlockSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Nemo Protocol hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/nemo-protocol
https://itokenly.com/hacks/nemo-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.