CryptoReal
CASE FILE — May 23, 2025

How a Single Token Deposit Unraveled Sui's Largest DEX in a $223 Million Liquidity Exploit

On May 22, 2025, Cetus Protocol — the largest decentralized exchange on the Sui network — lost roughly $223 million after attackers found a way to abuse a rounding flaw in the math underlying its concentrated-liquidity pools. The exploit didn't rely on a zero-day bug, oracle manipulation, or any exotic smart-contract trickery. It came down to a single miscalculation in the get_liquidity_from_a function, which let an attacker convert a deposit of just one token into an almost incomprehensibly large liquidity position.

01A quiet Thursday turns into a rout

The first public sign of trouble came from the account HODLFM, which flagged in the early hours of Thursday that USDC on Sui had depegged to zero and that liquidity was being pulled from pools while SUI tokens were dumping. Within minutes the situation was unmistakable: pools across the ecosystem were being drained, and token prices fell by roughly 80% even as Bitcoin was hitting new highs elsewhere. Meme tokens BULLA, HIPPO, and LOFI were among the first casualties.

Sui Network and Cetus both issued brief acknowledgments, describing what was happening as "an incident." Every liquidity pool on Cetus's AMM was affected before the situation was brought under control.

02The mechanics: turning a rounding error into infinite liquidity

A technical write-up from Verichains later laid out exactly how the exploit worked, and the underlying idea turned out to be almost trivially simple:

  1. Flash loan. The attacker borrowed 56,700 SUI, which — per the nature of flash loans — had to be repaid within the same transaction.
  2. A deliberately narrow price range. They opened a liquidity position spanning ticks 300,000 to 300,200 — a band only 200 ticks wide.
  3. A minimal deposit. Into that narrow range, they deposited exactly 1 SCA token.
  4. Exploiting the formula. The get_liquidity_from_a function is meant to translate a token deposit into a corresponding liquidity amount. But with a tick range that tight, the formula's denominator approached zero — and dividing by a number that close to zero produced a wildly inflated result. According to a later analysis by Dedaub, Cetus did have overflow protections in place, but they didn't cover this specific calculation path, leaving an opening the attacker exploited precisely.

The result: that single SCA token generated a liquidity position of 10,365,647,984,364,446,732,462,244,378,333,008 units — on the order of 10³⁴.

  1. Double withdrawal. The attacker then withdrew from that inflated position twice: once to cover the flash-loan repayment, and a second time as pure profit. A flaw in Cetus's accounting allowed the same LP position to be redeemed twice. The attacker repeated this pattern across essentially every pool on the protocol.

03Moving the money

The attacker's addresses have been identified as follows:

Drained LP tokens were systematically converted to USDC, and more than $60 million was bridged from Sui to Ethereum via Wormhole, converting into close to 21,000 ETH in the process. A subsequent batch transfer moved 20,000 ETH to a separate, previously unused wallet (0x0251536BfcF144B88e1aFa8fe60184Ffdb4cAF16), recorded in this transaction.

Tally:

Sums referenced in this case file
  • Total stolen: $223 million
  • Frozen by Sui validators: $162 million
  • Remaining unrecovered: $60+ million

04Validators step in — outside normal protocol rules

What set this incident apart from most DeFi hacks was Sui's response. Rather than relying on a signed transaction or contract-level logic, validators used a built-in emergency mechanism to collectively vote to freeze $162 million while the attack was still in progress, treating the attacker's address as untouchable at the consensus layer. It worked quickly, but it also raised questions about decentralization: the funds were quarantined by validator agreement, not through any on-chain rule the attacker had broken in a way the protocol itself could enforce.

The shock spread quickly to other Sui-based exchanges. Bluefin said it had "temporarily paused actions on Bluefin Spot as a precautionary measure," and Momentum announced it had "paused all activities on Momentum as a precautionary measure" in response to the Cetus exploit. Broader token dumps of at least 75% were reported across much of the Sui ecosystem in the hours that followed.

05Audits that missed the crack in the foundation

Barely a month before the exploit, on April 24, Cetus had publicized that it had completed multiple audit rounds with three separate top-tier firms. Movebit and Otter had audited the protocol roughly two years earlier; Zellic's audit was completed April 11 — just 41 days before the hack.

Zellic's co-founder said on social media that the firm couldn't share full details of an evolving situation but confirmed "the bug was out of scope for our audit." Zellic later told Rekt directly: "The vulnerability was not part of the scope Zellic audited. For public details that we're at liberty to disclose, the vulnerability was part of the integer-mate library in the checked_shlw method. But the integer-mate library was not included in the scope of our audit." In other words, the flaw sat in a shared math library that none of the audits had actually reviewed.

06An on-chain offer, then a bounty

With $60 million still outside their control, Cetus and Inca Digital took the unusual step of addressing the attacker directly on-chain. The proposal, posted publicly and signed by both parties, offered a whitehat arrangement: the attacker could keep 2,324 ETH (about $6 million) as a bounty, return the rest, and face no legal pursuit or further tracking. The offer carried a deadline — if the funds were moved off-ramp or mixed, the companies said they would escalate globally.

By Friday, there had been no reply. Cetus posted an update noting the silence and encouraging the attacker to "sincerely consider" the offer. Shortly after, with backing from Inca Digital and financial support from the Sui Foundation, Cetus announced a separate $5 million bounty for information leading to the identification and arrest of the attacker.

07A shared vulnerability across the ecosystem

The story didn't end with Cetus. Using its Revela Move Decompiler, Verichains published a follow-up report showing that the same flawed checked_shlw(u256) function had been copied into other Sui projects:

  • Kriya — approximately $10M in TVL, carrying the same bug, patched quietly after the Cetus incident.
  • FlowX — approximately $4.6M in TVL, same bug, fixed shortly afterward.
  • Turbos Finance — approximately $10.3M in TVL, containing the vulnerable code but in a code path that was never actually invoked.

Verichains summarized the risk bluntly: "dead code is not safe code." Kriya and FlowX moved quickly to deploy fixes once alerted. Turbos maintained that its contracts were independent of Cetus's and that the exploit method wouldn't have worked against its system. Combined, the three protocols carrying the shared flaw represented roughly $24.6 million in exposed TVL — and it's unclear whether other, undiscovered instances of the same copy-pasted function exist elsewhere.

08Summary

A single SCA token, a 200-tick price range, and a division operation that approached zero were enough to generate over 10³⁴ units of phantom liquidity and drain $223 million from Cetus's pools. Sui's validators managed to freeze $162 million mid-attack through an emergency, non-standard consensus action, but more than $60 million had already crossed the Wormhole bridge to Ethereum before it could be stopped. The root cause traced back to a shared math library, integer-mate, that fell outside the scope of every audit Cetus had commissioned — and the same flawed function was later found sitting in at least three other Sui protocols.

CetusSui Network
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.