Sitemap

Incident Summary and Compensation Plan

8 min readJun 27, 2025

Silakan scroll ke bawah untuk membaca versi Bahasa Indonesia

Dear Nusa Community,

Over the past few days, we have faced one of the most challenging moments in our journey. In the midst of rapid and unexpected changes caused by a targeted attack on the Nusa platform, your patience and support have been our greatest strength. From the bottom of our hearts, we thank you for standing with us.

Incident Chronology

An attacker identified a vulnerability in the current system and exploited the available liquidity in the Nusa lending market using the token MMETA. By using MMETA as collateral and artificially inflating its price, the attacker was able to drain significant amounts of liquidity from the platform in the form of other tokens including BTC, ETH, SOL, POL, DOGE, USDT, BNB, CAKE, and IDRX, accounting for nearly 76% of the total pool.

Following the exploit, the attacker reversed the price of MMETA back to its original level. With the market no longer actively managed by developers, MMETA became illiquid, making it nearly impossible to execute collateral liquidations.

On the day of the incident, we took immediate action by disabling the withdraw and borrow features to contain further damage and limit user impact. A snapshot of all balances was taken at that moment to ensure a fair and transparent reference point.

The next day, after careful evaluation of all risks and recovery possibilities, we made the difficult but necessary decision to permanently shut down the lending market to avoid cascading liquidations and begin a structured path toward ecosystem recovery.

After the Impact

This event was a heavy blow to Nusa. However, we remain committed to the integrity we have upheld for years and to the community that has grown with us. We are taking concrete steps to minimize the impact on affected users and to restore what was lost.

We have completed a thorough calculation of all assets in the lending market including borrow positions based on the snapshot taken on the day of the incident. In addition, weโ€™ve included supply and repay transactions that occurred between the snapshot and the moment we halted features, to ensure accuracy and fairness.

๐Ÿ“Š You can access the detailed compensation data here:
Compensation Sheet

Compensation and Repayment Process

We will return user funds based on the original assets supplied to the lending market. These funds will be claimable on the platform after all outstanding loans have been resolved.

If you currently have an active borrow position, there are two repayment options available:

๐Ÿ”น Option 1: Automatic Repayment Using Supplied Assets

We will automatically deduct a portion of your supplied assets to cover your outstanding loan. This will be done proportionally across the assets you supplied.

Example:

  • Total supply: $20,000 in BTCB, ETH, and POL
  • Total borrow: $10,000
  • Borrow ratio: 50%
  • You will receive compensation equal to 50% of each of your supplied assets

No action is needed if you choose this option. You will be automatically processed after the loan repayment window ends.

๐Ÿ”น Option 2: Manual Repayment Using USDT (BSC)

You may also choose to fully repay your borrow manually using USDT on the BSC network.

To proceed:

๐Ÿ—“ The repayment window will run from June 27 to July 10, 2025.

โš ๏ธ Important Notice:

Only proceed with payments through our official ticket on Discord.

Tickets are only handled by the Nusa official account or accounts with the admin role.

Do NOT respond to or send any payment to unofficial accounts claiming to be admins.

Any payment made outside this procedure is not our responsibility. Stay alert and always verify before taking action.

Check Admin Role on the Profile Account
Payments are only processed through the #๐ŸŽซ|open-ticket channel

Lessons Learned

๐Ÿ”น Stronger Token Curation Aligned with Lending Market V2
We are curating the list of tokens in the lending market more carefully, which is already aligned with our vision for Lending Market V2. The upcoming version will focus on serving real-world financial needs using blockchain technology, prioritizing stablecoins and blue-chip assets. By moving forward with this plan, we aim to reduce exposure to volatile or illiquid tokens and prevent similar risks.

๐Ÿ”น Deeper Community Involvement and Feedback Integration
We recognize the need to be more attentive and responsive to our users. Moving forward, we are committed to involving the community more meaningfully in our development process, ensuring that feedback directly shapes the direction of Nusa and fosters shared ownership of the platform.

๐Ÿ”น Enhanced Risk Monitoring and Emergency Response
This incident underlined the importance of faster detection and response. We will improve our on-chain monitoring, implement automated circuit breakers, and establish clearer emergency protocols to prevent and contain abnormal activity as early as possible.

๐Ÿ”น More Robust Infrastructure and Price Mechanism
The price manipulation highlighted vulnerabilities in price feed mechanisms. We are working to improve the reliability of oracles and liquidity safeguards, especially for newer or lower-liquidity assets, to reduce the risk of systemic impact from price-based exploits.

๐Ÿ”น Transparent and Timely Communication Standards
Clear, structured communication during emergencies is essential. We are committed to maintaining proactive and transparent updates in critical moments, ensuring users are informed and supported throughout.

Closing Statement

This incident has tested us deeply, challenging our systems, our values, and our responsibility to you. But through it all, our commitment remains: to protect our users, to uphold transparency, and to rebuild stronger.

We are not stopping here. With the lessons we have learned, we are taking action to build a better, more resilient lending market that prioritizes security, integrity, and long-term sustainability for the Nusa community.

Thank you for your continued support.
Team Nusa

Beberapa hari terakhir menjadi salah satu momen paling berat dalam perjalanan Nusa. Di tengah perubahan mendadak dan cepat akibat serangan yang ditujukan langsung ke platform Nusa, kesabaran dan dukungan kalian menjadi kekuatan terbesar kami. Dari hati yang paling dalam, kami mengucapkan terima kasih karena tetap bersama kami.๐Ÿ™

Kronologi Kejadian

Seseorang telah menemukan celah di sistem dan memanfaatkan likuiditas yang ada di lending market Nusa lewat token MMETA.
Dengan menjadikan MMETA sebagai kolateral dan memanipulasi harganya, pelaku berhasil menarik likuiditas dalam bentuk token lain seperti BTC, ETH, SOL, POL, DOGE, USDT, BNB, CAKE, dan IDRX โ€” total sekitar 76% dari seluruh pool.

Setelah itu, harga MMETA dikembalikan ke level normal, tapi karena token ini sudah tidak dikelola secara aktif, pasar MMETA jadi illiquid alias susah dijual, sehingga proses likuidasi kolateral pun terhambat.

Pada hari kejadian, kami langsung menonaktifkan fitur withdraw dan borrow untuk mencegah kerugian lebih lanjut. Kami juga langsung mengambil snapshot seluruh saldo pengguna di saat itu sebagai acuan yang adil dan transparan.

Keesokan harinya, setelah mengevaluasi semua risiko dan skenario pemulihan, kami perlu mengambil keputusan yang berat: menutup lending market secara permanen demi mencegah kerugian berkelanjutan dan memulai proses pemulihan yang lebih terstruktur.

Dampak Kejadian

Kejadian ini jadi pukulan besar buat kami. Tapi kami tetap berkomitmen untuk menjaga integritas yang sudah kami bangun selama ini, dan mendukung komunitas yang tumbuh bersama Nusa.

Kami sudah menghitung semua porsi aset dan pinjaman berdasarkan snapshot. Termasuk transaksi supply dan repay yang terjadi setelah snapshot sampai fitur dihentikan, hal ini dilakukan untuk memastikan akurasi dan keadilan saat pengembalian dana.

๐Ÿ“Š Lihat data lengkap kompensasi di sini:
Dokumen Kompensasi

Proses Kompensasi & Pengembalian Dana

Dana pengguna akan dikembalikan berdasarkan aset awal yang disupply di lending market.
Dana ini bisa diklaim di platform setelah semua pinjaman diselesaikan.

Terdapat 2 opsi bagi pengguna yang masih punya pinjaman aktif:

๐Ÿ”น Opsi 1: Otomatis Dipotong dari Aset Supply
Kami akan otomatis memotong sebagian aset pengguna untuk melunasi pinjaman. Jumlah potongannya akan proporsional sesuai total supply dan borrow.

Contoh:

  • Total supply: $20.000 (BTCB, ETH, POL)
  • Total borrow: $10.000
  • Borrow ratio: 50%
    Kamu akan menerima kompensasi 50% dari masing-masing aset yang kamu supply.

โœ… Kamu tidak perlu melakukan apapun untuk opsi ini. Proses akan dilakukan secara otomatis setelah masa repay selesai.

๐Ÿ”น Opsi 2: Repay Manual Pakai USDT (BSC)
Jika ingin melunasi pinjaman secara manual, bisa menggunakan token USDT di jaringan BSC.

Langkahnya:

  1. Buka tiket di Discord kami: https://discord.xyz/nusa_finance
  2. Minta proses repay manual
  3. Tim kami akan memberikan alamat wallet & langkah selanjutnya

๐Ÿ“… Masa repay dibuka dari 27 Juni sampai 10 Juli 2025

โš ๏ธ Informasi Penting:

Mohon hanya melakukan pembayaran melalui channel tiket resmi kami di Discord.

Tiket hanya akan ditangani oleh akun resmi Nusa atau akun yang mendapat role admin.

Jangan pernah membalas atau mengirim pembayaran ke akun tidak resmi yang mengaku sebagai admin.

Segala bentuk pembayaran yang dilakukan di luar prosedur ini bukan tanggung jawab kami. Tetap waspada dan selalu lakukan verifikasi sebelum bertindak.

Cek Role Admin Pada Akun Profile
Pembayaran hanya dilakukan pada channel #๐ŸŽซ|open-ticket

Pelajaran Penting

๐Ÿ”น Memperketat Kurasi Token untuk Lending Market V2
Ke depannya, kami akan lebih selektif dalam memilih token untuk lending. Fokus ke aset stabil & blue chip, agar risiko volatilitas bisa ditekan. Ini sejalan dengan visi Lending Market V2.

๐Ÿ”น Keterlibatan Komunitas yang Lebih Aktif
Kami sadar, masukan dari komunitas itu penting. Ke depannya, proses pengembangan Nusa akan lebih terbuka untuk feedback agar semua merasa memiliki platform ini.

๐Ÿ”น Pemantauan Risiko dan Respons Darurat Lebih Cepat
Kami akan meningkatkan monitoring on-chain, memasang fitur pemutus otomatis (circuit breaker), dan sistem darurat yang lebih tanggap untuk deteksi lebih awal.

๐Ÿ”น Perbaikan Infrastruktur & Mekanisme Harga
Manipulasi harga kemarin menunjukkan perlunya oracle dan sistem harga yang lebih kuat, terutama untuk token baru atau illiquid.

๐Ÿ”น Standar Komunikasi Darurat Lebih Transparan
Kami akan terus prioritaskan komunikasi yang cepat dan jelas saat krisis, agar pengguna tetap merasa aman dan selalu mendapatkan informasi secara jelas.

Penutup

Insiden ini menjadi ujian yang berat bagi kami โ€” menguji sistem, nilai, dan tanggung jawab kami terhadap kalian. Namun, di tengah semua ini, komitmen kami tidak akan berubah: kami akan terus berusaha untuk melindungi pengguna, menjunjung tinggi transparansi, dan membangun kembali platform dengan lebih kuat.

Kami tidak berhenti di sini. Dari pengalaman ini, kami mengambil pelajaran penting untuk membangun ekosistem lending yang mengedepankan keamanan, integritas, dan mengedepankan manfaat berkelanjutan jangka panjang bagi komunitas Nusa.

Terima kasih atas kepercayaan dan dukungan kalian sejauh ini.
Tim Nusa Finance

--

--

Nusa Finance
Nusa Finance

Written by Nusa Finance

One stop DeFi solution you will ever need with complete feature of DeFi available in one platform!

No responses yet