Nemo Protocol introduces NEOM debt tokens to compensate users hit by a $2.59 million exploit on September 7.Nemo Protocol introduces NEOM debt tokens to compensate users hit by a $2.59 million exploit on September 7.

Nemo Protocol rolls out debt token plan for $2.6M hack victims

4 min read

Sui-based yield trading platform Nemo Protocol has announced a debt token compensation program for users affected by a $2.59 million exploit on September 7. The repayment plan comes after the project’s team admitted an unaudited code change left its system vulnerable to attacks.

In a blog post published Sunday on Notion, Nemo revealed a three-step recovery plan based on the issuance of NEOM debt tokens. The program is meant to return value to victims over time through a dedicated redemption pool funded by recovered assets, liquidity loans, and investments.

Users will receive NEOM tokens pegged 1:1 to the value of their losses in USD terms, based on an onchain snapshot taken when the protocol was paused. 

While we would have preferred to reimburse everyone directly in USD, we do not have sufficient funds or capital raised to do so, which is why we adopted the debt token strategy as the most viable path forward,” the yield trading protocol team wrote.

Nemo protocol issues three-step recovery path

The first phase of the recovery plan will see users reclaim the residual value left in compromised pools through a one-click function. The assets will be transferred into new, multi-audited smart contracts managed jointly by Nemo and its partners.

The second phase is the distribution of NEOM tokens, where, after completing the migration process, victims will simultaneously receive debt tokens equivalent to their losses. For example, a $1 loss translates to one NEOM token.

The last phase gives them choices of how to handle their NEOM. Those affected by the hack can immediately exit through automated market makers or hodl the tokens while awaiting recovery from frozen or reclaimed funds.

Nemo has also launched a dedicated portal to support affected users, a one-stop module with three main features, including eligibility and loss display. Once a user connects their wallet, the system automatically identifies positions on all affected pools and displays three figures: original asset value, residual value, and total loss.

Another is a one-click claim tool, where users can transfer all residual liquidity provider tokens and yield tokens into secure contract pools with a single confirmation.

Last but not least is the NEOM claim module, which shows the exact number of debt tokens allocated to each user based on their total loss and an option to “claim NEOM.”

Nemo exploiter took advantage of flawed smart contract

According to a post-mortem report from Nemo, a malicious actor used a flaw in Nemo’s smart contract design to execute the hack. Blockchain security company PeckShield reported that the attacker stole Circle’s USDC stablecoin, bridging the tokens from Arbitrum to Ether before dispersing them through several laundering addresses.

On the protocol’s smart contract lies a flaw lay function which helps the trading platform reduce slippage. The code, called “get_sy_amount_in_for_exact_py_out,” was added onchain in January without the necessary audit from smart contract firm Asymptotic. 

Even when an upgrade was installed in April to tighten deployment checks, the vulnerable code had already been embedded in production. The attacker initiated cross-chain transfers at 16:10 UTC on September 7 via Wormhole’s Circle cross-chain transfer protocol (CCTP). 

In total, $2.59 million of Nemo’s funds was rapidly siphoned using flash loans from pools including sUSDC, sbUSDT, and sSUI.

Asymptotic’s team identified the vulnerability in a preliminary report delivered to Nemo on August 11. However, the platform conceded that it failed to address the issue in time before attackers found the loophole. 

After releasing a full prognosis of the exploit, Nemo has been coordinating with blockchain security teams and centralized exchanges (CEXs) to freeze stolen assets. 

KEY Difference Wire helps crypto brands break through and dominate headlines fast

Market Opportunity
TokenFi Logo
TokenFi Price(TOKEN)
$0.00309
$0.00309$0.00309
-4.83%
USD
TokenFi (TOKEN) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Tom Lee’s BitMine Hits 7-Month Stock Low as Ethereum Paper Losses Reach $8 Billion

Tom Lee’s BitMine Hits 7-Month Stock Low as Ethereum Paper Losses Reach $8 Billion

The post Tom Lee’s BitMine Hits 7-Month Stock Low as Ethereum Paper Losses Reach $8 Billion appeared on BitcoinEthereumNews.com. In brief Shares of BitMine Immersion
Share
BitcoinEthereumNews2026/02/06 04:47
Headwind Helps Best Wallet Token

Headwind Helps Best Wallet Token

The post Headwind Helps Best Wallet Token appeared on BitcoinEthereumNews.com. Google has announced the launch of a new open-source protocol called Agent Payments Protocol (AP2) in partnership with Coinbase, the Ethereum Foundation, and 60 other organizations. This allows AI agents to make payments on behalf of users using various methods such as real-time bank transfers, credit and debit cards, and, most importantly, stablecoins. Let’s explore in detail what this could mean for the broader cryptocurrency markets, and also highlight a presale crypto (Best Wallet Token) that could explode as a result of this development. Google’s Push for Stablecoins Agent Payments Protocol (AP2) uses digital contracts known as ‘Intent Mandates’ and ‘Verifiable Credentials’ to ensure that AI agents undertake only those payments authorized by the user. Mandates, by the way, are cryptographically signed, tamper-proof digital contracts that act as verifiable proof of a user’s instruction. For example, let’s say you instruct an AI agent to never spend more than $200 in a single transaction. This instruction is written into an Intent Mandate, which serves as a digital contract. Now, whenever the AI agent tries to make a payment, it must present this mandate as proof of authorization, which will then be verified via the AP2 protocol. Alongside this, Google has also launched the A2A x402 extension to accelerate support for the Web3 ecosystem. This production-ready solution enables agent-based crypto payments and will help reshape the growth of cryptocurrency integration within the AP2 protocol. Google’s inclusion of stablecoins in AP2 is a massive vote of confidence in dollar-pegged cryptocurrencies and a huge step toward making them a mainstream payment option. This widens stablecoin usage beyond trading and speculation, positioning them at the center of the consumption economy. The recent enactment of the GENIUS Act in the U.S. gives stablecoins more structure and legal support. Imagine paying for things like data crawls, per-task…
Share
BitcoinEthereumNews2025/09/18 01:27
European Blockchain Convention Drives Digital Finance Revival Amid 90% Blockchain Job Postings Decline

European Blockchain Convention Drives Digital Finance Revival Amid 90% Blockchain Job Postings Decline

The post European Blockchain Convention Drives Digital Finance Revival Amid 90% Blockchain Job Postings Decline appeared on BitcoinEthereumNews.com. This content is provided by a sponsor. PRESS RELEASE. Global leaders convene in Barcelona showcasing resilience as EU advances digital euro and fintech investment reaches €3.6bn in H1, 2025. Barcelona, Spain, September 22nd — The 11th European Blockchain Convention (EBC11) will gather global leaders in Barcelona on October 16-17 to challenge perceptions of European decline […] Source: https://news.bitcoin.com/european-blockchain-convention-drives-digital-finance-revival-amid-90-blockchain-job-postings-decline/
Share
BitcoinEthereumNews2025/09/23 07:16