Nemo, a DeFi protocol on Sui, suffered a $2.59 million asset loss due to security vulnerabilities in its flash_loan and get_sy_amount_in_for_exact_py_out functions. The breach occurred after developers launched new features without adequate audits, leaving known risks unaddressed. Attackers exploited these vulnerabilities, transferring most of the stolen funds to Ethereum via a cross-chain bridge. In response, Nemo has frozen its core functionality and submitted patches for emergency audit. The team is also working on a user compensation and asset tracking plan.