Neemo Exploit Reimbursement Plan

Let me share a fact and my understanding, sir.

All of the nrETH (114.53 ETH) was initially stolen by the hacker, but 91.634 ETH of it (roughly 80% of stolen nrETH) was returned through the white-hat offer.

On the other hand, the ETH that was drained from DeFi protocols using nsASTR was sent to Tornado Cash and has not been recovered. So I strongly believe recovered ETH should be allocated to nrETH holders.

If both Person A and Person B had their wallets stolen, and the thief returned only Person A’s wallet, should Person A be forced to share their recovered money with Person B? I don’t think so.

In the Split Model, around a 70% discount ratio for nrETH holders, while nsASTR holders receive only about a 20% discount.
It ignores the ownership of nrETH holders while fully respecting the ownership of nsASTR holders, resulting in nrETH holders suffering disproportionately—more than three times the loss(discount rate) compared to nsASTR holders. This is totally unfair.

So, I strongly believe that “2. Split Model” is absolutely NOT FAIR.

Thank you very much. The “Estimated Discount” has been clarified.

One more point I would like to clarify is whether the model originally proposed is to repay from the assets currently protected in Phase 1 and repay the remainder over the long term in Phase 2.

Based on the context and the “Conclusion,” I believe this understanding is correct, but personally, I was unable to confirm it due to insufficient clarification.

2 Likes

Thank you for sharing your perspective.

If both Person A and Person B had their wallets stolen, and the thief returned only Person A’s wallet, should Person A be forced to share their recovered money with Person B?

However, this is not the case. A slight tweak to your example would be more representative of the current situation. As follows:

Person A puts a credit card with a $10,000 value and Person B puts a credit card with a value of $100 into a pot. The pot was stolen. Person A was able to call the bank to deactivate the card, but not before $3,000 has already been lost. Person B was unable to do the same because there is no such service provided by his bank. The theft found person B and returned him $80. Should Person B keep the entire $80 to himself? I think not. But this is what “1. Asset Link Model” is proposing, which is unfair in my opinion.

Therefore, I believe "2. Split Model” is the fairest option.

1 Like

You really understand the situation, thank you very much.
He did not explain clearly how Defi liquidity consumption is calculated, because regardless of the currency, the exchange rate for liquidity depletion will not be 1:1.11. None of this was explained clearly.

In addition, the loss amount stated in the Neemo announcement is also inconsistent.

1 Like

The reality is that we have no other choice.
That’s how I feel.

1 Like

Thank you for your reply.

They have never been in the same pot.
The returned ETH was solely from the stolen nrETH.

The hacker used multiple wallets, and the following are completely separate:

Wallet 1: The wallet from which nrETH was withdrawn, and 80% of it was returned.
Wallet 2: The wallet that minted nsASTR, drained DeFi protocols, bridged 99 ETH and 166,027 USDC to Ethereum, and then sent them to Wallet 3.
Wallet 3: The wallet that sent the ETH received from Wallet 2 to Tornado Cash.

The address detaills are below:
Wallet 1: 0xb750e3165de458eae09904cc7fad099632860b0f
Wallet 2: 0x198b2c4e31186569de4f8058d4871534845bb299
Wallet 3: 0x4ec65e4dbe6e53ee4938aef2b173b38763d3bc2b

3 Likes

Also, please confirm the following onchain message.
The person who withdrew nrETH and the one who drained nsASTR seem to be different individuals.

https://etherscan.io/idm?addresses=0xdf902f5c5ecac2c387dfc122fa415eb07356b9d8,0xb750e3165de458eae09904cc7fad099632860b0f&type=1

Thank you for the information.

If you take a step back, technically they are in the same pot (i.e funds invested in Neemo Finance). It doesn’t really matter how many wallets were used by the hacker, how many hackers were involved, or how the hacker orchestrated the exploit. What holds true is that both nsASTR and nrETH holders put our funds into Neemo Finance, and funds were lost.

What I am trying to convey is that funds recovered from hacker should be shared to all affected parties. Just because ASTR discount rate is lower than nrETH purely by virtue of the effort by the Main Council to protect the funds, we cannot dismiss the rights of nsASTR holder to share the recovered amount returned by the hacker.

2 Likes

they are in the same pot (i.e funds invested in Neemo Finance)

hmm…
The protected ASTR is also part of the “funds invested in Neemo Finance” as you say, right?
Yet their ownership is recognized.
If Person A’s stolen wallet is returned but their ownership is not recognized and the funds are treated as belonging to everyone, I believe that would mean the ownership of nrETH holders is being ignored.

That is where I emphasized earlier: Asset protected ≠ asset recovered

To your context, Person A’s stolen wallet was not returned, it was protected through the unique nature of nsASTR being a LST of ASTR, where the Main Council can intervene, which they did in time. However, the same cannot be said for nrETH. If there was a function to protect nrETH from being exploited, I would agreed that such protected nrETH belongs to nrETH holders.

The main (and only) difference between “1. Asset Link Model” and "2. Split Model” and the point of discussion is what should we do with the recovered fund? That is where I reiterate my stance that recovered funds should be shared.

1 Like

With that said, despite our differing opinions, I truly appreciate the open discussion and the respectful tone being used. This is the essence of how a forum discussion should be - Open and respectful to one another. Thank you.

I’m not convinced, but since this seems to be heading toward a deadlock, I will refrain from further replies.
Thank you as well for the open discussion and the respectful tone throughout.

1 Like

Yes, your understanding is correct.

1 Like

Hey @SeiyaChida

Why did you reverse options 1 and 2 from your proposal?
This renders obsolete all comments mentioning these options and can mislead many people!

2 Likes

@SeiyaChida
Who is actually allowed to vote? Only the people affected by the hack or anyone who connects to the website?

Apologies regarding the reorder. I’ve written multiple posts on all the platforms and modified, so the order may have shifted unintentionally but I had absolutely no intention to mislead.

That said, everything has been explained in the column, all names are clearly stated, and all items are documented. The current order, including on Subsquare reflects the correct and final structure.

But the Subsquare cannot be edited once published. Let me know what actions you’d recommend. I’m happy to adjust.

In the off-chain vote, anyone can participate and cast their vote for the options. However, the on-chain vote is is for ASTR holders.

1 Like

@SeiyaChida

To what extent can you ensure that the users affected by the issue take part in the election and not just someone who has astar in their wallet?

I find option 2 unfair, as is option 4. Option 3 could theoretically be the most equitable, but it would be unfair to Astr holders. I understand that option 2 could be the most fair and equitable, and that the loss is similar, and that the money could be recovered in the long term.

To Neemo founder,
Have you try to Astar treasury to loan the missing $ASTR?
all 4 compensation methods result in users actively bearing the loss.
this loss was caused by neemo’s mistake. Have you ever thought about taking responsibility for it?
Your first priority is to find a way to compensate users 100%, rather than coming up with some confusing solutions.

To Astar team,
Can you proactively offer help to users?
Neemo is the largest LST on the $ASTR token. you have also promoted them.
Neemo will seriously affect the soneium defi ecosystem. If users do not receive 100% compensation for this incident, no one will dare to use soneium’s other defi projects.
The Astar team should take the initiative to stand with users.

please help us! thank you!

6 Likes