Nemo, a DeFi protocol built on the Sui ecosystem, released an incident report stating that security vulnerabilities in the flash_loan and get_sy_amount_in_for_exact_py_out functions within the contract were exploited by attackers, resulting in a loss of approximately $2.59 million. The attack stemmed from developers launching new features without sufficient audits and failing to promptly address known risks. The majority of funds were transferred to Ethereum via a cross-chain bridge. The protocol's core functionality has been frozen, and the vulnerability patch has been submitted for emergency audit. The team is developing a user compensation and asset tracking plan. Earlier news broke that Nemo, a DeFi protocol built on the Sui ecosystem, suffered an attack resulting in a loss of approximately $2.4 million. The attacker had transferred USDC from Arbitrum to Ethereum via Circle.