{"investigation":{"slug":"numa","entity_name":"numa.","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"numa. (stylized with a period) is a non-custodial DeFi protocol on Arbitrum and Sonic that issues LST-backed synthetic assets (nuUSD, nuBTC, nuETH, nuGOLD) through a burn-and-mint tokenomics model. The protocol suffered two separate exploits in 2025 — a $506K price manipulation attack in April and a $313K collateral valuation exploit in August — resulting in cumulative losses exceeding $800K and a token price decline of approximately 99% from its peak. ZachXBT has flagged the entity in the context of trust intelligence monitoring.","sections":[{"content":"numa. is a decentralized synthetics protocol that operates primarily on Arbitrum and later expanded to the Sonic blockchain. It enables users to deposit liquid-staking tokens (LSTs) into vaults in exchange for the native $NUMA token, which can then be burned to mint synthetic assets collectively called nuMoney — including nuUSD, nuBTC, nuETH, and nuGOLD. The protocol advertises zero-slippage trading between synthetics, native yield via LST backing, and interest-free lending with leverage options up to 10x. The collateralized debt position system uses cNuma as an internal collateral unit, whose price is derived from the formula (EthBalance - synthValueInEth) / circulatingNuma. The team has not publicly disclosed founder identities or team composition in official documentation. The protocol is integrated with Chainlink for price feed infrastructure.","heading":"Protocol Overview","sources":[{"url":"https://numa.money/","name":"numa.money","type":"other","credibility":3},{"url":"https://numa-1.gitbook.io/numa-v3-white-paper/introduction/summary","name":"numa-1.gitbook.io","type":"other","credibility":3},{"url":"https://www.chainlinkecosystem.com/ecosystem/numamoney","name":"chainlinkecosystem.com","type":"other","credibility":3},{"url":"https://coinpaprika.com/coin/numa-numa/","name":"coinpaprika.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 18, 2025 at approximately 9:00 PM UTC, the numa. protocol on Arbitrum suffered a price manipulation exploit resulting in the loss of approximately 292.96 rETH, valued at roughly $506,000–$527,000 at the time of the attack. The attacker exploited the protocol's sell-burn-lock mechanism: a flash loan was used to invoke the sell() function, which burned $NUMA tokens and reduced total circulating supply, artificially inflating the token's internal price. The attacker then called lockNumaSupply() to lock in the manipulated valuation, enabling them to borrow protocol assets at favorable rates before withdrawing the funds for profit. The affected contract was 0x9857127d6987a177d87c13d2dfdaa771bf625a69 on Arbitrum; the exploit transaction hash was 0x74a19463e3cc1d131a92599f2ff28effe13064d7c7480c851e7249708de40e3c. Stolen funds were bridged from Arbitrum to Ethereum via multiple bridges and subsequently laundered through Tornado Cash. The security platform Hypernative detected the threat more than seven minutes before execution — a window sufficient for intervention — but no preventive action was taken. The team discovered the attack approximately one hour after execution when a team member noticed an unusual price spike on the $NUMA token. Protocol lending and liquidation functions were immediately paused. The team subsequently committed to compensating affected users through a combination of vault rewards (~35 rETH), a $100,000 external contribution, and direct team and protocol funds. The team stated they would not make themselves whole so that external users could be made whole first. Approximately 1.49 million $NUMA owed to external users was prioritized for recovery. The $NUMA token reached an all-time low of approximately $0.13 on April 21, 2025, three days after the exploit.","heading":"April 2025 Exploit — Flash Loan Price Manipulation ($506K)","sources":[{"url":"https://numa.money/blog/update-on-recent-security-incident-affecting-numa","name":"numa.money","type":"other","credibility":3},{"url":"https://numa.money/blog/incident-update-and-moving-forward","name":"numa.money","type":"other","credibility":3},{"url":"https://www.hypernative.io/blog/hypernative-detection-506k-exploit-of-numa-money-on-arbitrum","name":"hypernative.io","type":"other","credibility":3},{"url":"https://olympixai.medium.com/dexodus-zora-numa-946k-lost-to-replays-access-bugs-and-locked-in-prices-40c37b78391c","name":"olympixai.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On August 10, 2025, numa. suffered a second exploit, this time on the Sonic blockchain, resulting in a loss of approximately $313,000 (74.3 ETH). The attacker exploited a flaw in the VaultManager's collateral valuation logic. The cNuma token price is calculated using the formula (EthBalance - synthValueInEth) / circulatingNuma. By flash-minting nuBTC tokens using flash-loaned stS assets from Beets Vault, the attacker artificially inflated synthValueInEth from approximately 160,092 to 1,351,479 ETH-equivalent. This inflated value suppressed the numerator in the cNuma price formula, causing cNuma's collateral valuation to collapse from 7.579e18 to 2.115e18, rendering multiple previously adequately-collateralized positions suddenly liquidatable. The attacker liquidated five victim accounts, seizing approximately 58,800 $NUMA tokens and 121,800 stS tokens, then converted them to stablecoins, repaid flash loans, and bridged 74.3 ETH to Ethereum. These proceeds were then deposited into Tornado Cash. The primary attacker wallet was identified as 0xEf1df44E122872d0feF75644AFc63a5C35F97674. Attack contracts included 0xd4de62a8DD0F0D43ca8886E0393e159D5E5e38e6 and 0x3041652a157fd9230eda8e741c103e4688a37c05. Security analysts noted this vulnerability stemmed from the same underlying design flaw as the April exploit: the ability to manipulate synthValueInEth without proportional backing, which had not been fully remediated between incidents. CertiK and Verichains both published post-incident analyses.","heading":"August 2025 Exploit — Collateral Valuation Logic Flaw ($313K)","sources":[{"url":"https://blog.verichains.io/p/numa-incident-analysis","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://www.certik.com/blog/numa-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://nominis.io/insights/nominis-monthly-report-crypto-attacks-in-september-2025","name":"nominis.io","type":"other","credibility":3}],"severity":"medium"},{"content":"The $NUMA token experienced severe price deterioration throughout 2025, declining approximately 99.43% over the calendar year. The token recorded an all-time low of approximately $0.13 on April 21, 2025, days after the first exploit. Price data from multiple aggregators confirms the token's near-total value collapse. The repeated security failures contributed to a sustained loss of market confidence. CoinGecko, Coinbase, and other data providers list the token as active but reflect minimal liquidity and market capitalization. The Hypernative report characterized the April exploit as an entirely avoidable loss, noting its detection window of over seven minutes prior to execution underscores a gap between detection infrastructure and operational response within the protocol team.","heading":"Token Performance and Market Impact","sources":[{"url":"https://www.coingecko.com/en/coins/numa","name":"coingecko.com","type":"other","credibility":3},{"url":"https://www.coinbase.com/price/numa","name":"coinbase.com","type":"other","credibility":3},{"url":"https://www.hypernative.io/blog/hypernative-detection-506k-exploit-of-numa-money-on-arbitrum","name":"hypernative.io","type":"other","credibility":3},{"url":"https://beincrypto.com/price/numa/price-prediction/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"numa. engaged Sherlock as its primary auditor, and the post-April-exploit response included a Sherlock audit review as a prerequisite for reopening Arbitrum lending and launching on Sonic. However, the August 2025 exploit — which occurred after the protocol's Sonic expansion and after structural changes were purportedly implemented — demonstrates that the underlying design vulnerability in the VaultManager's collateral pricing formula was not fully resolved by the changes made following the first incident. Both CertiK and Verichains independently analyzed the August exploit and concluded that a thorough security audit including adversarial stress-testing was essential before deploying modified protocol versions to production. The protocol's own incident report acknowledged a structural modification was needed to prevent further manipulation, specifically citing the removal of the ability to short $NUMA as the primary corrective measure for the Sonic deployment. The recurrence of a materially similar attack vector within approximately four months of the first exploit raises significant questions about the adequacy of the remediation process. No third-party audit report has been publicly linked by the team in connection with the post-April protocol changes.","heading":"Security Posture and Audit History","sources":[{"url":"https://numa.money/blog/incident-update-and-moving-forward","name":"numa.money","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/numa-incident-analysis","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://www.certik.com/blog/numa-incident-analysis","name":"certik.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In both the April 2025 and August 2025 exploits, the attacker routed stolen proceeds through Tornado Cash, the sanctioned Ethereum mixing service. In April 2025, the attacker used multiple bridges to move assets from Arbitrum to Ethereum before depositing into Tornado Cash. In August 2025, 74.2 ETH was deposited into Tornado Cash after bridging from Sonic to Ethereum. The consistent use of Tornado Cash in both incidents is consistent with the involvement of a sophisticated threat actor seeking to obscure fund flows. These patterns were noted in analyses published by Hypernative, CertiK, and Verichains. No law enforcement action or asset recovery has been publicly reported in connection with either exploit.","heading":"Funds Laundering and On-Chain Traceability","sources":[{"url":"https://www.hypernative.io/blog/hypernative-detection-506k-exploit-of-numa-money-on-arbitrum","name":"hypernative.io","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/numa-incident-analysis","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://www.certik.com/blog/numa-incident-analysis","name":"certik.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The numa. team has not publicly disclosed the identities of founders or core contributors in official documentation, the protocol whitepaper, or the project website as of the date of this report. Post-exploit communications were published on the protocol's blog and directed users to an official Telegram group for further engagement. The team demonstrated responsiveness in pausing affected functionality within one hour of discovering the April exploit, and committed to absorbing losses to make external users whole — a commitment the team stated would not extend to their own holdings. No governance token separate from $NUMA has been identified. No regulatory filings, legal entity disclosures, or formal corporate structure have been published by the protocol. The anonymous team structure limits accountability in the event of future incidents.","heading":"Team Transparency and Governance","sources":[{"url":"https://numa.money/blog/update-on-recent-security-incident-affecting-numa","name":"numa.money","type":"other","credibility":3},{"url":"https://numa.money/blog/incident-update-and-moving-forward","name":"numa.money","type":"other","credibility":3},{"url":"https://numa.money/","name":"numa.money","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-12","event":"numa. protocol launches on Arbitrum with LST-backed synthetics (nuUSD, nuBTC, nuETH, nuGOLD) and burn-and-mint tokenomics.","source":"","date_original":"2024-12-01"},{"date":"2025-04-18","event":"First exploit: attacker uses flash loan to manipulate $NUMA internal price via sell-burn-lock mechanism, stealing approximately 292.96 rETH (~$506K). Hypernative detected the attack 7+ minutes prior to execution. Stolen funds bridged to Ethereum and laundered through Tornado Cash.","source":""},{"date":"2025-04-18","event":"Numa team discovers exploit approximately one hour after execution. Protocol pauses lending and liquidation functionality.","source":""},{"date":"2025-04-21","event":"$NUMA token hits all-time low of approximately $0.13, down roughly 60% from pre-exploit price.","source":""},{"date":"2025-04-21","event":"Team publishes compensation plan: ~35 rETH in vault rewards, $100K external contribution, and direct team/protocol funds to make 1.49M $NUMA owed to external users whole.","source":""},{"date":"2025-05","event":"Team announces Sonic blockchain launch planned for end of May 2025, with Sherlock audit review required before deployment. Arbitrum lending to reopen after Sonic launch.","source":"","date_original":"2025-05-01"},{"date":"2025-08-10","event":"Second exploit: attacker flash-mints nuBTC to inflate synthValueInEth, collapsing cNuma collateral prices and triggering forced liquidations of five victim accounts on Sonic. Approximately $313K (74.3 ETH) stolen. Funds bridged to Ethereum and deposited into Tornado Cash.","source":""},{"date":"2025-08","event":"Olympix publishes analysis of the August exploit, categorizing it as a locked-in price manipulation vulnerability. CertiK and Verichains publish independent post-mortems.","source":"","date_original":"2025-08-01"}],"sources_used":[{"url":"https://numa.money/","name":"numa.money","type":"other","archive_url":"http://web.archive.org/web/20260606141802/https://numa.money/","credibility":3,"archive_timestamp":"2026-06-06T14:18:02+00:00"},{"url":"https://numa-1.gitbook.io/numa-v3-white-paper/introduction/summary","name":"numa-1.gitbook.io","type":"other","archive_url":"http://web.archive.org/web/20260509170345/https://numa-1.gitbook.io/numa-v3-white-paper/introduction/summary","credibility":3,"archive_timestamp":"2026-05-09T17:03:45+00:00"},{"url":"https://www.chainlinkecosystem.com/ecosystem/numamoney","name":"chainlinkecosystem.com","type":"other","archive_url":"https://web.archive.org/web/20260829084509/https://www.chainlinkecosystem.com/ecosystem/numamoney","credibility":3,"archive_timestamp":"2026-08-29T08:45:09+00:00"},{"url":"https://coinpaprika.com/coin/numa-numa/","name":"coinpaprika.com","type":"other","archive_url":"https://web.archive.org/web/20260829074203/https://coinpaprika.com/coin/numa-numa/","credibility":3,"archive_timestamp":"2026-08-29T07:42:03+00:00"},{"url":"https://numa.money/blog/update-on-recent-security-incident-affecting-numa","name":"numa.money","type":"other","archive_url":"http://web.archive.org/web/20260118201732/https://numa.money/blog/update-on-recent-security-incident-affecting-numa","credibility":3,"archive_timestamp":"2026-01-18T20:17:32+00:00"},{"url":"https://numa.money/blog/incident-update-and-moving-forward","name":"numa.money","type":"other","archive_url":"http://web.archive.org/web/20260215144046/https://numa.money/blog/incident-update-and-moving-forward","credibility":3,"archive_timestamp":"2026-02-15T14:40:46+00:00"},{"url":"https://www.hypernative.io/blog/hypernative-detection-506k-exploit-of-numa-money-on-arbitrum","name":"hypernative.io","type":"other","archive_url":"http://web.archive.org/web/20260515142634/https://www.hypernative.io/blog/hypernative-detection-506k-exploit-of-numa-money-on-arbitrum","credibility":3,"archive_timestamp":"2026-05-15T14:26:34+00:00"},{"url":"https://olympixai.medium.com/dexodus-zora-numa-946k-lost-to-replays-access-bugs-and-locked-in-prices-40c37b78391c","name":"olympixai.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.verichains.io/p/numa-incident-analysis","name":"blog.verichains.io","type":"other","archive_url":"http://web.archive.org/web/20260419203810/https://blog.verichains.io/p/numa-incident-analysis","credibility":3,"archive_timestamp":"2026-04-19T20:38:10+00:00"},{"url":"https://www.certik.com/blog/numa-incident-analysis","name":"certik.com","type":"other","archive_url":"http://web.archive.org/web/20260422170936/https://www.certik.com/blog/numa-incident-analysis","credibility":3,"archive_timestamp":"2026-04-22T17:09:36+00:00"},{"url":"https://nominis.io/insights/nominis-monthly-report-crypto-attacks-in-september-2025","name":"nominis.io","type":"other","archive_url":"http://web.archive.org/web/20260606051236/https://www.nominis.io/insights/nominis-monthly-report-crypto-attacks-in-september-2025","credibility":3,"archive_timestamp":"2026-06-06T05:12:36+00:00"},{"url":"https://www.coingecko.com/en/coins/numa","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coinbase.com/price/numa","name":"coinbase.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://beincrypto.com/price/numa/price-prediction/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:21.977639+00:00","updated_at":"2026-08-30T12:05:00.781889+00:00"}}