Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

$223 Million Stolen in Cetus Protocol Hack

Hackers exploited a vulnerability in Cetus Protocol, a liquidity provider on the SUI blockchain.

A vulnerability in the smart contract for liquidity pools allowed hackers to steal roughly $223 million in virtual assets from cryptocurrency exchange Cetus Protocol.

The incident occurred on May 22 and led to Cetus immediately pausing its smart contract, but not before the hackers were able to siphon both native SUI tokens and other tokens.

The attackers exploited a vulnerability in an open source library used in the liquidity provider’s smart contract, manipulated pool prices, and proceeded to drain token reserves, repeating the process several times, Cetus explains in a post-mortem report.

“By manipulating the pool’s tick and liquidity mechanisms, the attacker successfully drained a significant portion of assets across multiple iterations of the exploit,” it notes.

The hackers first swapped USDT to USDC, two stablecoins issued by Tether and Circle, respectively, then bridged to the Ethereum blockchain and converted the funds to the native asset, blockchain analytics firm Elliptic says.

Cetus identified two SUI wallet addresses controlled by the attackers, as well as two Ethereum Wallets storing portions of the stolen funds, after they were converted.

Advertisement. Scroll to continue reading.

The hackers stole approximately $223 million, but Cetus said it managed to freeze $162 million of the assets. This makes the incident the second largest crypto heist of the year, after the $1.5 billion Bybit hack.

“We are working with the Sui Foundation and other ecosystem members right now on next-step solutions, with the goal of recovering the remaining stolen funds,” Cetus said.

The firm offered the hackers a “whitehat settlement”: they can keep $6 million as a bounty, if they return the rest of the stolen Ethereum and SUI assets.

Cetus notes that it has been working with its partners on a recovery plan, aiming to restore liquidity withdrawals and other functionality as soon as possible.

Late Monday, the exchange said it had plans in place that would fully reimburse for the lost assets.

“Using our cash and token treasuries, we are now in a position to fully cover the stolen assets currently off-chain if the locked funds are recovered through the upcoming community vote,” the company posted on X. “ This includes a critical loan from the Sui Foundation, making a 100% recovery for all affected users possible.”

Related: FBI Says North Korea Hacked Bybit as Details of $1.5B Heist Emerge

Related: German Authorities Take Down Crypto Swapping Service eXch

Related: North Korean Cryptocurrency Thieves Caught Hijacking Zoom ‘Remote Control’ Feature

Related: Malicious NPM Packages Target Cryptocurrency, PayPal Users

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.