{"investigation":{"slug":"nemo-yield-trading","entity_name":"Nemo Yield Trading","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Nemo Protocol is a Sui-based DeFi yield trading platform that suffered a $2.6 million exploit on September 7, 2025, caused by an unnamed developer who deployed unaudited code to mainnet while bypassing internal review processes. A security auditor had flagged a related vulnerability 27 days before the attack, which the team acknowledged it failed to address in time. The protocol's TVL has since collapsed to zero and it has been flagged as high-risk by trust intelligence sources.","sections":[{"content":"Nemo Protocol (also listed as Nemo Yield Trading on DeFiLlama) is a decentralized finance yield infrastructure protocol built on the Sui blockchain. The protocol enables yield tokenization by splitting yield-bearing assets into Principal Tokens (PT) and Yield Tokens (YT), allowing users to lock in fixed yields, speculate on future yield rates, or provide liquidity to earn fees. Additional products include Nemo Vaults (automated liquidity management), Nemo Swap (DEX aggregator), and a Point Market for loyalty rewards trading. The official X account was established in June 2022. The project completed the Sui Hydropower Accelerator program's first cohort in January 2025. Backers include Scallop, Bucket Protocol, Comma3 Ventures, AlphaFi, and Elevate, and the project received Sui Grants. Founder and CEO Alex Yeung is reported to maintain a limited online presence. As of mid-2026, the protocol shows zero TVL and zero active fee or revenue activity across all tracked timeframes on DeFiLlama.","heading":"Protocol Overview","sources":[{"url":"https://defillama.com/protocol/nemo-yield-trading","name":"defillama.com","type":"other","credibility":3},{"url":"https://iq.wiki/wiki/nemo-protocol","name":"iq.wiki","type":"other","credibility":3},{"url":"https://www.rootdata.com/Projects/detail/Nemo%20Protocol?k=MTM5NTE%3D","name":"rootdata.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 7, 2025 at approximately 16:00 UTC, Nemo Protocol was exploited for approximately $2.4 to $2.6 million in USDC and SUI tokens. The exploit was first publicly flagged by on-chain security firm PeckShield. The attack exploited two critical vulnerabilities simultaneously: (1) an internal flash loan function that was accidentally left exposed as public rather than restricted as private, and (2) a query function named 'get_sy_amount_in_for_exact_py_out' that was designed as read-only but was flawed in a way that allowed it to modify the internal state of the contract. The attacker combined these two vulnerabilities — using the exposed flash loan to borrow assets, then invoking the flawed query function to manipulate the contract's internal pricing state, draining assets from the SY/PT liquidity pool. Stolen assets were subsequently bridged from Sui to Ethereum via the Wormhole CCTP cross-chain transfer protocol. The majority of the stolen assets were held in a single attacker wallet on Ethereum. The protocol's total value locked (TVL) collapsed from approximately $6.3 million to $1.57 million as users withdrew over $3.8 million in USDC and SUI following the breach. The Nemo team detected unusual yields displaying over 30x returns within the first 30 minutes of the attack and paused the protocol via a multi-signature wallet.","heading":"September 2025 Exploit ($2.6 Million)","sources":[{"url":"https://www.coindesk.com/markets/2025/09/08/sui-based-yield-protocol-nemo-exploited-for-usd2-4m-in-usdc","name":"coindesk.com","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/nemo-protocol-hacked-2-4m-081422991.html","name":"finance.yahoo.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/369766/sui-nemo-protocol-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://crypto.news/nemo-protocol-2-6m-exploit-caused-by-developers-unaudited-code/","name":"crypto.news","type":"other","credibility":3},{"url":"https://coinfomania.com/nemo-protocol-exploit-steals-2-4-million-and-tests-defi-security/","name":"coinfomania.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The post-mortem released on September 11, 2025 revealed a chain of security failures beginning in January 2025. A developer submitted code containing unaudited features to auditor MoveBit while mixing previously audited fixes with unreviewed functionality, without disclosing the new additions to the auditors. The developer later deployed contract version 0xcf34 using a single-signature address (0xf55c) rather than the audit-confirmed contract hash, bypassing the internal multi-signature review process.\n\nSeparately, security firm Asymptotic flagged a critical vulnerability (classified C-2 in its preliminary report) on August 11, 2025 — 27 days before the exploit — warning that certain functions could modify contract state without proper authorization. The Nemo team has acknowledged that the developer dismissed the severity of the Asymptotic warning and that the team 'did not adequately address this security concern in a timely manner,' citing competing priorities. Cointelegraph reported the team's admission that the auditor had flagged the issue before the hack.\n\nThe protocol acknowledged it 'relied too heavily on past assurances without maintaining rigorous scrutiny at every step.' The single-signature deployment mechanism used by the developer was identified as a specific governance failure that allowed unreviewed code to reach mainnet.","heading":"Pre-Exploit Audit Failures and Developer Misconduct","sources":[{"url":"https://cointelegraph.com/news/2-6-million-lost-in-nemo-hack-due-to-unaudited-code-and-ignored-vulnerability","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/370273/nemo-protocol-unaudited-code-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://cryptonews.com/news/nemo-protocol-blames-2-6m-exploit-on-developer-who-deployed-unaudited-code/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://bitcoinethereumnews.com/tech/auditor-flagged-issue-before-2-59m-nemo-hack-team-admits/","name":"bitcoinethereumnews.com","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/nemo-protocol-blames-2-6m-083310308.html","name":"finance.yahoo.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Nemo Protocol announced a compensation program for affected users centered on the issuance of a new debt token called NEOM. Users receive one NEOM token for every US dollar lost, calculated from an on-chain snapshot taken at the time the protocol was paused. The team acknowledged it 'does not have sufficient funds or capital raised' to reimburse users directly in USD, citing the debt token approach as the most viable path forward.\n\nThe recovery program operates in three steps: (1) users migrate residual assets from compromised pools to new multi-audited smart contracts while simultaneously receiving NEOM tokens equal to their loss amount; (2) NEOM holders can either sell immediately via a Sui-based AMM liquidity pool paired with USDC, or hold the tokens pending further fund recovery; (3) any funds recovered from the attacker are deposited into a multi-party managed Redemption Pool, from which NEOM holders can claim proportional shares.\n\nNemo committed to providing bi-weekly progress updates and launching a public dashboard to track redemptions and token burns. A 10% white-hat bounty was offered to the attacker for voluntary fund return. As of mid-2026, social media reports indicate the vault migration process was completed and users could claim NEOM tokens, though the NEOM token's market value was reported to be trading below its $1.00 peg, meaning victims have not been made fully whole.","heading":"Compensation Program and NEOM Debt Token","sources":[{"url":"https://cryptonews.com/news/nemo-protocol-issues-neom-debt-tokens-to-compensate-2-6m-exploit-victims/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/370581/nemo-protocol-debt-token-program-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/nemo-protocol-debt-token-program-hack-victim/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://crypto.news/nemo-protocol-to-issue-debt-token-to-compensate-2-6m-hack-victims/","name":"crypto.news","type":"other","credibility":3},{"url":"https://coinpedia.org/news/nemo-protocol-introduces-neom-token-to-compensate-2-4m-hack-losses/","name":"coinpedia.org","type":"other","credibility":3}],"severity":"medium"},{"content":"As of mid-2026, Nemo Yield Trading shows zero TVL on DeFiLlama with no active fee or revenue generation across any tracked timeframe. Cumulative lifetime fees for the protocol amount to approximately $14,296. The protocol was flagged by trust intelligence sources, including AVOID.NET, as high-risk following the exploit. The NEOM debt token compensation approach has been criticized as an inadequate substitute for direct reimbursement, particularly given the token's trading below its $1.00 target peg. The combination of a pre-known unaddressed vulnerability, single-signature deployment bypassing governance controls, and an auditor's warning that was dismissed by a developer constitutes a pattern of critical security governance failure. No information is publicly available indicating the attacker has returned any funds.","heading":"Protocol Status and Risk Assessment","sources":[{"url":"https://defillama.com/protocol/nemo-yield-trading","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2025/09/08/sui-based-yield-protocol-nemo-exploited-for-usd2-4m-in-usdc","name":"coindesk.com","type":"other","credibility":3},{"url":"https://x.com/SmartDropFarmer/status/1998698715125571968","name":"x.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-06","event":"Nemo Protocol's official X account established; project founded.","source":""},{"date":"2025-01","event":"Developer submits code to MoveBit auditors without disclosing new unaudited features mixed into the submission. Protocol completes Sui Hydropower Accelerator first cohort.","source":""},{"date":"2025-08-11","event":"Security firm Asymptotic issues a C-2 severity warning flagging a vulnerability in Nemo's contract code that allows unauthorized state modification. The developer allegedly dismisses the severity and no fix is deployed.","source":""},{"date":"2025-09-07","event":"Exploit occurs at approximately 16:00 UTC. Attacker uses exposed flash loan function combined with flawed query function to drain approximately $2.4-2.6 million from the SY/PT liquidity pool. Stolen assets bridged to Ethereum via Wormhole CCTP. TVL collapses from $6.3M to $1.57M.","source":""},{"date":"2025-09-08","event":"PeckShield publicly flags the breach. Nemo Protocol confirms the attack and announces protocol pause. Nemo offers a 10% white-hat bounty to the attacker.","source":""},{"date":"2025-09-11","event":"Nemo Protocol releases post-mortem report, attributing the exploit to unaudited code deployed by an internal developer via single-signature address, and admitting the Asymptotic warning was not adequately addressed.","source":""},{"date":"2025-09-14","event":"Nemo Protocol announces the NEOM debt token compensation program, issuing one NEOM per dollar lost. Team acknowledges it lacks capital for direct USD reimbursement.","source":""},{"date":"2026-05","event":"Social media reports indicate the vault migration was completed and NEOM tokens are claimable. NEOM reportedly trades below its $1.00 peg. Protocol TVL remains at zero.","source":""}],"sources_used":[{"url":"https://defillama.com/protocol/nemo-yield-trading","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250913233346/https://defillama.com/protocol/nemo-yield-trading","credibility":3,"archive_timestamp":"2025-09-13T23:33:46+00:00"},{"url":"https://iq.wiki/wiki/nemo-protocol","name":"iq.wiki","type":"other","archive_url":"http://web.archive.org/web/20260413021913/https://iq.wiki/wiki/nemo-protocol","credibility":3,"archive_timestamp":"2026-04-13T02:19:13+00:00"},{"url":"https://www.rootdata.com/Projects/detail/Nemo%20Protocol?k=MTM5NTE%3D","name":"rootdata.com","type":"other","archive_url":"https://web.archive.org/web/20260830035302/https://www.rootdata.com/Projects/detail/Nemo%20Protocol?k=MTM5NTE%3D","credibility":3,"archive_timestamp":"2026-08-30T03:53:02+00:00"},{"url":"https://www.coindesk.com/markets/2025/09/08/sui-based-yield-protocol-nemo-exploited-for-usd2-4m-in-usdc","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260115002147/https://www.coindesk.com/markets/2025/09/08/sui-based-yield-protocol-nemo-exploited-for-usd2-4m-in-usdc","credibility":3,"archive_timestamp":"2026-01-15T00:21:47+00:00"},{"url":"https://finance.yahoo.com/news/nemo-protocol-hacked-2-4m-081422991.html","name":"finance.yahoo.com","type":"other","archive_url":"https://web.archive.org/web/20260829225625/https://finance.yahoo.com/news/nemo-protocol-hacked-2-4m-081422991.html","credibility":3,"archive_timestamp":"2026-08-29T22:56:25+00:00"},{"url":"https://www.theblock.co/post/369766/sui-nemo-protocol-exploit","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20251129062650/https://www.theblock.co/post/369766/sui-nemo-protocol-exploit","credibility":3,"archive_timestamp":"2025-11-29T06:26:50+00:00"},{"url":"https://crypto.news/nemo-protocol-2-6m-exploit-caused-by-developers-unaudited-code/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20251011062552/https://crypto.news/nemo-protocol-2-6m-exploit-caused-by-developers-unaudited-code/","credibility":3,"archive_timestamp":"2025-10-11T06:25:52+00:00"},{"url":"https://coinfomania.com/nemo-protocol-exploit-steals-2-4-million-and-tests-defi-security/","name":"coinfomania.com","type":"other","archive_url":"http://web.archive.org/web/20260829225259/https://coinfomania.com/nemo-protocol-exploit-steals-2-4-million-and-tests-defi-security/","credibility":3,"archive_timestamp":"2026-08-29T22:52:59+00:00"},{"url":"https://cointelegraph.com/news/2-6-million-lost-in-nemo-hack-due-to-unaudited-code-and-ignored-vulnerability","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260310185651/https://cointelegraph.com/news/2-6-million-lost-in-nemo-hack-due-to-unaudited-code-and-ignored-vulnerability","credibility":3,"archive_timestamp":"2026-03-10T18:56:51+00:00"},{"url":"https://www.theblock.co/post/370273/nemo-protocol-unaudited-code-exploit","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20251012034226/https://www.theblock.co/post/370273/nemo-protocol-unaudited-code-exploit","credibility":3,"archive_timestamp":"2025-10-12T03:42:26+00:00"},{"url":"https://cryptonews.com/news/nemo-protocol-blames-2-6m-exploit-on-developer-who-deployed-unaudited-code/","name":"cryptonews.com","type":"other","archive_url":"http://web.archive.org/web/20251018223712/https://cryptonews.com/news/nemo-protocol-blames-2-6m-exploit-on-developer-who-deployed-unaudited-code/","credibility":3,"archive_timestamp":"2025-10-18T22:37:12+00:00"},{"url":"https://bitcoinethereumnews.com/tech/auditor-flagged-issue-before-2-59m-nemo-hack-team-admits/","name":"bitcoinethereumnews.com","type":"other","archive_url":"https://web.archive.org/web/20260829023536/https://bitcoinethereumnews.com/tech/auditor-flagged-issue-before-2-59m-nemo-hack-team-admits/","credibility":3,"archive_timestamp":"2026-08-29T02:35:36+00:00"},{"url":"https://finance.yahoo.com/news/nemo-protocol-blames-2-6m-083310308.html","name":"finance.yahoo.com","type":"other","archive_url":"http://web.archive.org/web/20250916185704/https://finance.yahoo.com/news/nemo-protocol-blames-2-6m-083310308.html","credibility":3,"archive_timestamp":"2025-09-16T18:57:04+00:00"},{"url":"https://cryptonews.com/news/nemo-protocol-issues-neom-debt-tokens-to-compensate-2-6m-exploit-victims/","name":"cryptonews.com","type":"other","archive_url":"http://web.archive.org/web/20251010091845/https://cryptonews.com/news/nemo-protocol-issues-neom-debt-tokens-to-compensate-2-6m-exploit-victims/","credibility":3,"archive_timestamp":"2025-10-10T09:18:45+00:00"},{"url":"https://www.theblock.co/post/370581/nemo-protocol-debt-token-program-exploit","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20250929232845/https://www.theblock.co/post/370581/nemo-protocol-debt-token-program-exploit","credibility":3,"archive_timestamp":"2025-09-29T23:28:45+00:00"},{"url":"https://www.cryptopolitan.com/nemo-protocol-debt-token-program-hack-victim/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20260124024554/https://www.cryptopolitan.com/nemo-protocol-debt-token-program-hack-victim/","credibility":3,"archive_timestamp":"2026-01-24T02:45:54+00:00"},{"url":"https://crypto.news/nemo-protocol-to-issue-debt-token-to-compensate-2-6m-hack-victims/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20251017010118/https://crypto.news/nemo-protocol-to-issue-debt-token-to-compensate-2-6m-hack-victims/","credibility":3,"archive_timestamp":"2025-10-17T01:01:18+00:00"},{"url":"https://coinpedia.org/news/nemo-protocol-introduces-neom-token-to-compensate-2-4m-hack-losses/","name":"coinpedia.org","type":"other","archive_url":"http://web.archive.org/web/20251205080829/https://coinpedia.org/news/nemo-protocol-introduces-neom-token-to-compensate-2-4m-hack-losses/","credibility":3,"archive_timestamp":"2025-12-05T08:08:29+00:00"},{"url":"https://x.com/SmartDropFarmer/status/1998698715125571968","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:16.161089+00:00","updated_at":"2026-08-30T03:54:58.063959+00:00"}}