Skip to main content

Title:Sui Network Reels After $200M Cetus DEX Exploit: What Happened and What’s Next?

Sui Network Reels After $200M Cetus DEX Exploit: What Happened and What’s Next?

The Sui blockchain ecosystem has been rocked by one of its most devastating events yet—an exploit on Cetus, its largest decentralized exchange (DEX), that resulted in the loss of over $200 million in crypto assets. The incident, which unfolded rapidly, has sparked widespread panic, caused a sharp selloff in Sui-based tokens, and reignited debates around DeFi security and stablecoin issuer response times.


What Happened in the Cetus Exploit on Sui?

On May 22, 2025, hackers targeted vulnerabilities in the smart contracts of Cetus Protocol, the most prominent DEX on the Sui network. According to Deddy Lavid, CEO of blockchain security firm Cyvers, the attackers used spoof tokens to exploit pricing and reserve calculation mechanisms.

By manipulating the DEX’s oracle system and faking price signals, the hacker was able to drain multiple liquidity pools—including the high-liquidity SUI/USDC pool—by extracting real crypto assets in exchange for worthless tokens.

> “The attacker deployed spoof tokens to distort price curves and trick the protocol into releasing real funds,” explained Lavid.



The Fallout: Massive Losses Across Sui Ecosystem

The impact was immediate and severe. Meme tokens on the Sui network experienced catastrophic losses:

Lofi (LOFI) plunged 76%

Sudeng (HIPPO) nosedived 80%

Squirtle (SQUIRT) collapsed 97%


The Cetus token (CETUS) itself crashed 53% within an hour of the exploit.

Data from DEX Screener reveals that 46 Sui-based tokens suffered double-digit losses in just 24 hours, making this one of the worst single-day performances for the ecosystem.


How Much Was Stolen in the Cetus Exploit?

Blockchain security firm PeckShield estimates that the total loss amounts to $200 million. Cyvers reports that the attacker currently holds:

$164 million in a wallet on the Sui network

$61.5 million bridged out as USDC on Ethereum


The attacker primarily used USDC, a widely adopted stablecoin, to exit the ecosystem. The speed and ease of bridging funds raised alarms within the community and called into question the response times of stablecoin issuers like Circle and Tether.


Cetus Response and Smart Contract Pause

Following the exploit, the Cetus team issued an emergency alert on X (formerly Twitter), stating that the DEX had been paused and was under investigation:

> “There was an incident detected on our protocol and our smart contract has been paused temporarily for safety. The team is investigating the incident at the moment.”



Pausing smart contracts is a standard emergency response in DeFi to prevent further damage, but many users were already impacted before the pause took effect.


Was It a Smart Contract Bug or Oracle Manipulation?

Initial messages leaked from the Cetus team’s Discord suggest the exploit may have stemmed from a bug in its oracle system. However, cybersecurity analysts including Cyvers confirm it was an oracle manipulation attack.

Oracles act as bridges between on-chain and off-chain data—especially prices. By injecting spoof tokens and manipulating the price feed, the attacker tricked the smart contracts into executing trades at false valuations, effectively siphoning real tokens in return for fake ones.


Stablecoin Issuers Under Fire: Why Wasn’t USDC Frozen Sooner?

One of the major criticisms that followed the hack centered around Circle, the issuer of USDC, for failing to freeze funds fast enough. On-chain investigator ZachXBT and others questioned why it took several hours before any action was taken to flag or freeze the hacked funds.

> “We’ve repeatedly urged stablecoin issuers to act on our real-time alerts. In this threat environment, delay is indistinguishable from inaction,” said Lavid.



This isn’t the first time Circle or Tether have been criticized for slow reaction times. Similar scrutiny followed the Bybit hack in February, where it took more than five hours to freeze funds.


CZ Weighs In, Sui Token Survives the Storm

Former Binance CEO Changpeng “CZ” Zhao commented on the situation, writing on X:

> “Not a pleasant situation. Hope everyone stays SAFU!”



Interestingly, despite the exploit’s magnitude, the SUI token itself remained surprisingly resilient. According to CoinGecko, SUI actually gained 2.2% over the past 24 hours. This suggests that while DeFi apps on the network took a hit, investor confidence in the Sui Layer 1 protocol may still be intact.



Key Takeaways From the $200M Sui Cetus Exploit

1. Smart Contract Security Still a Major Weak Point

DeFi protocols continue to be vulnerable to sophisticated attacks, especially those exploiting oracle mechanisms and pricing vulnerabilities. This reinforces the need for more robust audits, on-chain monitoring, and fail-safe mechanisms.

2. Stablecoin Issuers Must Act Faster

The speed at which stolen funds can be bridged and laundered means issuers like Circle and Tether need faster reaction protocols when alerted about hacks involving USDC or USDT.

3. Decentralized Finance Still Faces Centralized Bottlenecks

Despite being decentralized in theory, DeFi projects rely on centralized or semi-centralized elements—like oracles and stablecoins—that can introduce systemic risk if not handled properly.

4. Community Communication Is Critical

The slow and vague responses from the Sui and Cetus teams frustrated many users. Clearer, real-time updates and transparency during crisis events can help retain user trust.


What’s Next for Cetus and the Sui Ecosystem?

The situation is still unfolding. At the time of writing:

Cetus contracts remain paused.

Investigations are ongoing.

Funds are being tracked by security firms and community sleuths.

Pressure is mounting on Circle to act quicker in freezing bridged USDC from exploits.


Recovery plans—if any—have not yet been announced. Users with exposure to Cetus or affected tokens are advised to monitor official updates and avoid interacting with potentially compromised pools.

Conclusion: A Wake-Up Call for DeFi Security

The Cetus exploit on Sui is a stark reminder that the DeFi landscape remains fraught with risk. While innovation continues to expand what’s possible in decentralized finance, security often lags behind.

Projects must prioritize smart contract audits, oracle hardening, and proactive communication. Meanwhile, stablecoin issuers like Circle must take their gatekeeping role more seriously. In fast-moving threat environments, delayed action often equals no action.

As the dust settles, the broader crypto community will be watching closely to see how Cetus, Sui, and others in the ecosystem rebuild trust.

Comments

Popular posts from this blog

Solana Dominates DApp Revenue in Q2 2025 Despite Yearly Dip: Full Breakdown

Top Blockchain Platforms by DApp Revenue in 2025: Why Solana Is Still King Introduction In the dynamic world of blockchain and decentralized finance (DeFi), performance metrics like decentralized application (DApp) revenue offer a powerful lens into the real-world usage and growth of various blockchain networks. As per the latest data for the second quarter of 2025, Solana continues to assert its dominance, generating the highest DApp revenue among all chains — outpacing even Ethereum and Tron combined. This performance solidifies Solana’s position as a top-tier blockchain platform, even amid a notable year-over-year decline in revenue. Let’s break down the current rankings, analyze what’s driving Solana’s sustained leadership, and understand what this means for the future of decentralized applications. Solana Leads the DApp Ecosystem with $570M Revenue in Q2 2025 According to recent data from industry trackers, Solana DApps generated over $570 million in revenue during Q2...

Avalanche Partners with South Korea's Travel Wallet to Launch Korean Won Stablecoin

A major step toward programmable money and a new global payments system built on blockchain. Introduction As blockchain adoption accelerates worldwide, South Korea is emerging as a crucial hub for digital asset innovation. The latest move in the crypto world comes from Avalanche (AVAX), a popular Layer-1 blockchain platform, which has just announced a groundbreaking partnership with South Korea’s fintech platform, Travel Wallet. The two firms have signed a memorandum of understanding (MOU) to develop a Korean won-based stablecoin. With this, Avalanche aims to support the next wave of financial infrastructure in Asia’s booming digital economy. This development is significant not just for Korean users, but for the broader blockchain ecosystem, as it introduces a regulatory-compliant and programmable stablecoin tied to one of Asia’s most influential economies. Here’s a closer look at the partnership, the vision behind it, and what it could mean for the future of decentralized ...

Australia’s Project Acacia Moves Ahead: RBA Expands Testing for CBDC and Tokenized Assets

  RBA’s Digital Currency Pilot Enters Next Phase with 24 New Use Cases Introduction: A New Chapter in Australia’s Digital Currency Journey Australia has taken a bold step toward the future of finance with the expansion of Project Acacia, the Reserve Bank of Australia’s (RBA) pilot initiative for exploring central bank digital currencies (CBDC) and tokenized assets. As global interest in digital currencies and blockchain-backed assets continues to grow, this project marks a significant milestone for the country’s digital finance infrastructure. In this latest phase, the RBA aims to evaluate real-world use cases involving digital assets, in collaboration with major banks, fintechs, and regulators. With a total of 24 different test scenarios, Project Acacia is expected to offer valuable insights into how digital currencies can integrate with Australia’s financial markets. What is Project Acacia? Project Acacia is a collaborative effort led by the Reserve Bank of Australia...