Cetus Protocol Suffers $220M Exploit, Freezes Trading as Tokens Crash 80%

Cetus Protocol Exploit Drains $220M as Sui Validators Freeze $162M
TL;DR
- Cetus Protocol suffered an exploit on May 22, 2025, draining about $220 million from liquidity pools.
- Security researchers said the attacker used spoof tokens and manipulated liquidity calculations to withdraw real assets.
- Tokens across the Sui ecosystem plunged, with some falling as much as 97%.
- About $63 million was moved to Ethereum, while roughly $162 million was later frozen with help from Sui validators.
- The intervention helped limit further losses but triggered debate over Sui's decentralization and censorship resistance.
Cetus Protocol, a major decentralized exchange on Sui, suffered a roughly $220 million exploit on May 22, 2025, forcing the platform to halt trading and sending several ecosystem tokens sharply lower.
Early reports pointed to a possible oracle problem. Later security analysis indicated that the attacker used spoof tokens and manipulated the DEX's liquidity calculations to extract real assets.
The attack became one of the largest DeFi security incidents on Sui and raised questions about smart contract security, oracle design, and the network's ability to freeze stolen funds.
What Happened to Cetus Protocol?
Cetus first acknowledged an “incident” after unusual activity was detected across its liquidity pools.
The protocol quickly paused its smart contracts and trading functions while investigating the cause.
Early information was unclear.
Some initial estimates focused on about $11 million removed from the SUI/USDC pool. Broader blockchain analysis later showed that the attack affected multiple pools and involved roughly $220 million in assets.
PeckShield and other security researchers subsequently reported that the full loss was much larger than the first estimates suggested.
How Did the Cetus Exploit Work?
Security researchers said the attack involved manipulated or spoof tokens that interfered with Cetus's liquidity calculations.
Cyvers Security CEO Deddy Lavid said the attacker created counterfeit tokens and used them to distort price curves and reserve calculations.
The manipulated values reportedly allowed the attacker to withdraw legitimate assets from Cetus pools without providing equivalent value.
HackenProof CTO Alex Horlan also described a process involving fake token pairs and extremely low liquidity inputs.
The attacker could then repeatedly remove assets such as:
Early community discussion referred to the problem as an oracle bug. Later security analysis described the attack more broadly as manipulation of Cetus's pricing and liquidity mechanisms using spoof tokens.
This distinction matters because the incident was not simply a market price feed failing on its own. According to the later analysis, the attacker deliberately created conditions that caused the protocol to calculate incorrect asset values.
Cetus Trading Halts as Liquidity Disappears
The exploit quickly disrupted trading across Cetus.
Liquidity disappeared from several pools, including some that were not directly targeted. Cetus then stopped trading while the team investigated the attack.
Because Cetus was a major source of liquidity on Sui, the disruption spread across the ecosystem.
Prices on the Cetus DEX also became disconnected from prices on centralized exchanges as liquidity vanished and normal trading stopped.
The incident showed why thin or depleted liquidity can produce extreme price distortions on decentralized exchanges, even when the same token is trading normally elsewhere.
Sui Ecosystem Tokens Crash After Cetus Hack
Several tokens connected to Sui's DeFi ecosystem suffered major losses after the exploit.
Reported 24-hour declines included:
- SQUIRT: down 97%
- HIPPO: down 80%
- LOFI: down 76%
- CETUS: down 53%
A total of 46 tokens recorded double-digit losses during the period.
The sell-off reflected both depleted liquidity and uncertainty about whether other Sui-based DeFi applications could face similar risks.
SUI itself behaved differently.
Despite the attack, the token reportedly gained about 2.2% within 24 hours. The move contrasted sharply with the collapse in many smaller ecosystem tokens.
Where Did the Stolen Cetus Funds Go?
After draining the pools, the attacker began converting stolen SUI into USDC and moving assets away from the Sui network.
Tracking data showed that about $61.5 million to $63 million in USDC was transferred to Ethereum.
Security researchers Extractor and Lookonchain later reported that roughly $60 million was used to purchase around 20,000 ETH.
The assets were then transferred to another Ethereum wallet.
The move to Ethereum gave the attacker access to a larger ecosystem of decentralized services, including cross-chain and privacy-related infrastructure.
Early tracking also indicated that roughly $164 million remained in the attacker's Sui wallet before network intervention restricted further movement.
Sui Validators Freeze About $162 Million
The most controversial development came when Sui validators moved to prevent the attacker from transferring much of the remaining stolen cryptocurrency.
The Sui Foundation and Cetus said roughly $162 million in compromised assets had been effectively frozen.
Validators identified addresses linked to the attack and rejected transactions originating from them.
The intervention significantly increased the amount of potentially recoverable funds.
But it created another problem: if validators can block specific addresses, how decentralized and censorship-resistant is the network?
Critics argued that the ability of a relatively small validator set to stop transactions showed that the network could intervene directly when enough participants agreed.
Supporters of the action could point to its immediate benefit: more than $160 million in stolen assets were prevented from moving further.
The episode therefore created a difficult trade-off between fund recovery and decentralization.
Circle Faces Criticism Over USDC Response
The attack also put stablecoin issuers under scrutiny.
Onchain investigator ZachXBT criticized Circle over what he viewed as a slow response involving stolen USDC.
Cyvers CEO Deddy Lavid made a similar argument, saying security firms had repeatedly sent real-time alerts to stablecoin issuers without receiving rapid action.
“In this threat environment, delay is indistinguishable from inaction,” Lavid said.
The criticism reflects a recurring challenge after major crypto exploits: stolen assets can move across wallets and blockchains within minutes, while institutional responses can take much longer.
Sui's Response Raises Decentralization Questions
Sui Network provided limited additional public detail during the immediate aftermath, directing inquiries toward existing statements.
That left the validator intervention as one of the biggest issues emerging from the Cetus exploit.
A widely circulated criticism argued that allowing validators to freeze addresses may undermine censorship resistance.
The debate highlights a broader challenge for newer Layer-1 networks.
When an attacker steals hundreds of millions of dollars, validators may have the technical ability to intervene. Using that ability can protect users, but it also demonstrates that transactions are not necessarily unstoppable under all circumstances.
The Cetus incident put that trade-off into practice rather than leaving it as a theoretical debate.
What the Cetus Exploit Means for Sui DeFi
The $220 million Cetus exploit exposed risks that extend beyond a single decentralized exchange.
The attack highlighted weaknesses around:
- Liquidity calculations
- Pricing mechanisms
- Spoof token handling
- Smart contract validation
- Real-time exploit detection
- Cross-chain fund tracking
- Emergency validator intervention
Cetus said it would publish a full incident report covering the attack timeline, technical weaknesses, and measures designed to prevent similar exploits.
The event also showed how quickly a DeFi attack can spread beyond the compromised protocol. Liquidity disappeared, token prices collapsed, stolen funds crossed chains, stablecoin issuers faced pressure to intervene, and validators ultimately blocked addresses to stop further movement.
For Sui, recovering roughly $162 million could reduce the financial impact. But the larger questions remain.