Cetus Protocol Hit by $260 Million Hack on Sui blockchain
On May 22, the Cetus Protocol, a key decentralized exchange on the Sui blockchain, suffered a massive hack. The attack drained about $223 million, causing chaos in the Sui ecosystem. This event led to a sharp drop in SUIS price, from $4.19 to $3.62, a 14% decline within a day. The native CETUS token also fell from $0.26 to $0.15.
The exploit targeted the SUI/USDC liquidity pool. Initially,it seemed like an $11 million outflow.Though, the total loss reached around $260 million.The breach exposed a flaw in Cetus’s smart contract system, specifically its oracle design. Oracles provide real-time price data for fair trading. The hacker manipulated this system using spoof tokens like BULLA. these tokens skewed pricing curves, making assets appear undercollateralized.The attacker then extracted real tokens without adding value. The hacker moved $63 million in USDC to Ethereum, converting $58.3 million into ETH.
Cetus is crucial for Sui, with over 62,000 users and $7.15 million in daily fees. The sui blockchain’s total value locked dropped from $2.13 billion to $1.92 billion. The attacker, identified as “0xe28b50,” exploited the oracle’s pricing mechanism. This led to a liquidity drain, affecting Sui’s memecoins, with losses between 51% to 97%. The Sui ecosystem faced a liquidity crisis, impacting over 75% of the top 15 assets on the platform. The hack began at 3:52 AM PT, initially flagged as an $11 million outflow. The attacker used fake tokens to distort reserve balances. This made valuable assets seem undercollateralized, allowing the extraction of real tokens.
The Sui blockchain, launched in 2023, saw its native token, SUI, and other tokens like LOFI and HIPPO, losing value. The community is now assessing the damage and planning a response. The Sui ecosystem,including tokens like LBTC and AXOLcoin,saw prices collapse. The attacker moved $63 million in USDC to Ethereum. The community is investigating the structural flaws. The hack exposed vulnerabilities in the pricing mechanism. The attacker extracted real tokens without contributing value. The Sui ecosystem’s confidence is shaky,despite price stabilization. The hack highlighted the need for better security measures. The Sui community is now focusing on fixing these issues.
- Attack began at 3:52 AM PT.
For more details, check the Hacken Club’s analysis.
Sui Network Faces Major Exploit: $220 Million Lost
A significant security breach on the Sui blockchain has led to a loss of $220 million. The attack targeted the Cetus protocol, a decentralized finance platform. The hacker manipulated the system by injecting fake tokens,causing a massive financial drain.
The core issue lay in the smart contracts’ design. Functions like “addLiquidity,” “removeLiquidity,” and “swap” were exploited. These tools were meant to manage token ratios and pool values but didn’t check inputs properly. This allowed the attacker to introduce worthless tokens, like BULLA, which mimicked real assets but had no real value. This flaw let the attacker manipulate the protocol’s calculations, enabling them to withdraw large amounts of SUI and USDC with minimal real investment. The attacker’s strategy was simple yet effective. They used these fake tokens to skew the protocol’s internal accounting. This manipulation let them withdraw valuable assets at unfair rates.
How did it happen? The attacker took advantage of the lack of proper input validation. By adding these spoof tokens, they distorted the system’s calculations. This distortion let them extract SUI and USDC at favorable rates. The incident is a classic case of oracle manipulation. The system couldn’t tell the difference between real and fake assets.
On-chain activity spiked dramatically.Transactions jumped from $320 million on May 21 to nearly $2.9 billion the next day. The protocol’s design flaw became its weakness. The Move programming language, used for Sui’s smart contracts, usually protects against basic threats. However, this attack bypassed those protections. The protocol had no checks to stop tokens with no real value from affecting the system. Without safeguards, the protocol followed its rules blindly, leading to the massive loss.
Following the exploit, Cetus swiftly halted operations to stop further losses. They froze smart contracts around 4 AM PT on may 22. The team acknowledged the breach and promised a thorough inquiry. Yet, no detailed report has been released as of May 23.
The Sui Foundation and partners responded by freezing $162 million.
The Sui Foundation, validators, and partners collaborated to blacklist the attacker’s addresses. They froze about $162 million in stolen assets. Though, around $60 million to $98 million remains unrecovered. cetus offered a $6 million bounty to recover the funds. The proposal targets the ETH converted from the stolen USDC. The attacker has not responded publicly.
This incident sparked a debate on decentralization. Critics argue that the ability to freeze funds undermines true decentralization.
Validators’ Power in Sui Network Sparks Decentralization Debate
Recently, validators in the sui network took a significant step that raised eyebrows. They coordinated to address a specific issue, showing their influence over the network’s behavior. While this move was effective, it also sparked concerns about the level of control validators can exert.
Critics argue that such coordination challenges the core principle of decentralization. They fear that validator-driven censorship might be possible, casting doubt on the network’s true decentralization.This incident has led to questions about whether networks like Sui are genuinely decentralized or merely claim to be.
The coordination among validators has some worried. They believe it coudl lead to censorship, undermining the decentralized nature of the network.This situation has prompted a debate on the extent of validators’ power and the network’s commitment to decentralization.
Decentralization is a cornerstone of blockchain technology. It ensures no single entity has too much control. However, this event suggests that validators might have more power than previously thoght. This raises questions about the network’s integrity and the potential for centralized control.
It’s crucial to understand that this coordination could set a precedent. It highlights the need for clearer guidelines on validator roles.
For more insights, visit Sui Network’s official page.
