Nemo Hack
What happened
On September 8, 2025, Nemo Protocol, a Sui-based yield infrastructure and trading platform, was exploited for approximately $2.4 million in USDC stablecoins. The attacker subsequently bridged the stolen funds from Arbitrum to Ethereum, prompting Nemo to suspend all smart contract activity and investigate the security incident affecting their Market pool.
The attack targeted Nemo Protocol's lending infrastructure through what appears to be price manipulation techniques, resulting in the theft of $2.4 million in USDC from the platform's Market pool. Following the exploit, the attacker moved the stolen USDC tokens from Arbitrum to Ethereum via cross-chain bridges to obscure the transaction trail. Nemo Protocol responded by immediately suspending all smart contract activity while conducting an investigation into the root cause of the breach.
The platform confirmed that all vault assets remain secure despite the Market pool compromise. The exploit caused significant damage to the protocol's total value locked (TVL), which plummeted from over $6 million to $1.53 million according to DeFiLlama data. Nemo had previously announced scheduled maintenance for Monday and Tuesday, though the timing relationship to the exploit remains unclear.
The team has not yet publicly identified the specific vulnerability that enabled the attack.
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Report theblock.co
- report Report coindesk.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.