CoinInsight360.com logo CoinInsight360.com logo
America's Social Casino

crypto.news 2025-05-23 04:35:24

Sui-based Cetus Protocol offers $6M bounty to hacker after $223M exploit

Cetus Protocol, the largest decentralized exchange on the Sui blockchain, is offering a $6 million bounty to the hacker behind a massive $223 million exploit that occurred on May 22. In a May 22 follow-up statement accompanied by an on-chain message, the Cetus team confirmed they had identified the attacker’s Ethereum wallet and offered a “whitehat settlement” to recover user funds. The hacker is being asked to return 20,920 ETH and all frozen assets on Sui ( SUI ) in exchange for keeping 2,324 Ethereum ( ETH ), worth approximately $6 million, and immunity from legal action. Cetus said this is a time-sensitive offer and that if the funds are off-ramped or mixed, the deal is off. The team is coordinating with law enforcement, cybercrime specialists, the Sui Foundation, and regulators including FinCEN and the U.S. Department of Defense. Inca Digital, a cybersecurity firm, is leading the negotiation efforts. https://twitter.com/cetusprotocol/status/1925653859143172608?s=46&t=nznXkss3debX8JIhNzHmzw The breach exploited a vulnerability in Cetus’ pricing mechanism and impacted its concentrated liquidity market maker pools. The attacker used spoof tokens, which are fake or low-value assets with manipulated metadata, to inject tiny amounts of liquidity into trading pools. You might also like: Alleged Coinbase hacker trolls ZachXBT with on-chain message after swapping $42.5m BTC Because of the distortion of those pools’ internal accounting, the hacker was able to take out substantial quantities of valuable tokens, such as SUI and USD Coin ( USDC ), at incorrect exchange rates. The attacker deceived the system into believing the pools were balanced by carefully timing these spoof token deposits with complex flash swaps and price manipulation. As a result, they were able to drain substantial real assets without supplying equivalent value. Cetus had reportedly passed recent security audits prior to the hack. However, by exploiting internal pricing logic and economic assumptions rather than simple code errors, the attacker’s method evaded typical vulnerability scans. After initially draining $11 million from an SUI/USDC pool, the attacker quickly intensified the attack. They bridged more than $60 million in stolen funds to Ethereum and bought over 21,900 ETH. They currently have millions of SUI, ETH, and stablecoins in their wallets. The Sui ecosystem was severely damaged by the exploit. Smaller tokens like AXOL, HIPPO, and SQUIRT lost almost all of their value, while the SUI token dropped as much as 15%. CETUS, the token of Cetus, fell 20–33%. Trading volumes surged as users scrambled to withdraw funds. Cetus has paused smart contracts following the hack the hack and is attempting to secure its platform. The incident raises questions about the security of DeFi protocols on newer chains like Sui and Aptos ( APT ). Although these ecosystems offer innovation, analysts warn that vulnerabilities in complex DeFi logic remain a persistent risk. Read more: The Coinbase hack that shadowed its S&P rise — and the investigators who saw it coming

Loe lahtiütlusest : Kogu meie veebisaidi, hüperlingitud saitide, seotud rakenduste, foorumite, ajaveebide, sotsiaalmeediakontode ja muude platvormide ("Sait") siin esitatud sisu on mõeldud ainult teie üldiseks teabeks, mis on hangitud kolmandate isikute allikatest. Me ei anna meie sisu osas mingeid garantiisid, sealhulgas täpsust ja ajakohastust, kuid mitte ainult. Ükski meie poolt pakutava sisu osa ei kujuta endast finantsnõustamist, õigusnõustamist ega muud nõustamist, mis on mõeldud teie konkreetseks toetumiseks mis tahes eesmärgil. Mis tahes kasutamine või sõltuvus meie sisust on ainuüksi omal vastutusel ja omal äranägemisel. Enne nende kasutamist peate oma teadustööd läbi viima, analüüsima ja kontrollima oma sisu. Kauplemine on väga riskantne tegevus, mis võib põhjustada suuri kahjusid, palun konsulteerige enne oma otsuse langetamist oma finantsnõustajaga. Meie saidi sisu ei tohi olla pakkumine ega pakkumine