Nexo Smart Contract Exploited By Fake Uniswap V3 Pool

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Jump to navigation Jump to search

Notice: This page is a freshly imported case study from an original repository. While the original content had a similar format, some sections may not have been fully completed. Please help fill in any empty sections or any missing information you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

Nexo Logo/Website

Nexo is a leading digital asset platform offering a broad suite of financial services, including crypto savings, trading, lending, and wealth management, with over $11 billion in assets under management since its launch in 2018. However, a vulnerability in the smart contract function 0x94f82f54()—which lacked access controls and input validation—was exploited to redirect funds to a fake Uniswap V3 pool. Security firms SlowMist and TenArmor reported losses ranging from $31,535 to approximately $144.8K, citing multiple suspicious attacks. Despite these findings, Nexo has not publicly acknowledged or addressed the incident, and no recovery efforts have been reported.[1][2][3][4]

About Nexo

Nexo is a comprehensive digital asset platform that empowers individuals, businesses, and institutions to build and manage wealth in the crypto economy. Since its founding in 2018, Nexo has grown to manage over $11 billion in assets and operate in more than 150 jurisdictions. The platform offers a full suite of services from crypto savings and trading to credit lines, debit/credit cards, and private wealth solutions—all accessible through a single, streamlined app.

At its core, Nexo provides flexible and fixed-term savings options that allow users to earn daily compound interest—up to 16% annually—on a wide range of digital assets including BTC, ETH, USDT, and fiat-pegged stablecoins. For those seeking more active strategies, Nexo also offers Dual Investment products and high-leverage futures trading.

The platform goes beyond personal finance, supporting credit-backed liquidity solutions through crypto-collateralized loans, starting at just 2.9% interest. It also features the Nexo Exchange, where users can trade over 100 cryptocurrencies and set automated recurring buys. The Nexo Card enables real-time spending in both debit and credit modes, allowing users to earn up to 2% cashback without selling their crypto.

For high-net-worth individuals and corporate clients, Nexo Private delivers tailored wealth management, OTC trading, and customized credit services for portfolios starting at $100,000. Businesses can also build digital treasuries with institutional-grade security and 24/7 white-glove support.

The Reality

The Nexo smart contract contained a vulnerability where the 0x94f82f54() function lacked proper access control and input validation. This flaw could allow unauthorized users to call the function and manipulate its behavior. By bypassing authentication checks and providing manipulated input, an attacker could deceive the contract into treating a fake pool as legitimate.

What Happened

The Nexo smart contract was exploited due to missing access controls and input validation in the 0x94f82f54() function, allowing an attacker to redirect funds to a fake Uniswap V3 pool.

Key Event Timeline - Nexo Smart Contract Exploited By Fake Uniswap V3 Pool
Date Event Description
May 21st, 2025 10:31:54 AM MDT Sandwich Attack Transaction The sandwich attack transaction happens on the Binance smart chain.
May 21st, 2025 8:55:00 PM MDT SlowMist Security Alert Post SlowMist posts a security alert about "potential suspicious activity".

Technical Details

SlowMist attributes the attack root cause to a "lack of permission control", noting that "the contract was attacked by sandwich attacks".

Transaction hash: 0x3278b9ee1391269a22742d6b4a1289426d1245220ce8994fe32837cd251598f1

More specifically, the function 0x94f82f54() in the victim contract 0x0851 suffers from critical security flaws due to missing access control and inadequate input validation. These omissions make the function vulnerable to exploitation by unauthorized users. Specifically, the contract does not verify the identity or permissions of the caller, allowing anyone to invoke this sensitive function.

As a result of these vulnerabilities, an attacker was able to exploit the function to redirect or swap funds from the contract into a maliciously crafted or faked Uniswap V3 pool. By supplying manipulated input parameters, the attacker tricks the contract into treating the fraudulent pool as legitimate, enabling the unauthorized withdrawal or movement of assets.

Total Amount Lost

SlowMist reports amount of loss: $31,535, which appears to come from a screenshot they have generated.

TenArmor describes that there are actually "multiple suspicious attacks" "resulting in an approximately loss of $144.8K".

The total amount lost has been estimated at $145,000 USD.

Immediate Reactions

It does not appear that Nexo has addressed or mentioned the issue publicly.

Multiple firms such as TenArmor and SlowMist reported on the incident on the blockchain.

Ultimate Outcome

It does not appear that Nexo has addressed or mentioned the issue publicly.

Total Amount Recovered

There is no note on any recovery happening.

There do not appear to have been any funds recovered in this case.

Ongoing Developments

It does not appear that Nexo has addressed or mentioned the issue publicly.

Individual Prevention Policies

No specific policies for individual prevention have yet been identified in this case.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Policies for platforms to take to prevent this situation have not yet been selected in this case.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

No specific regulatory policies have yet been identified in this case.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References