Cetus loses $223 million on Sui, and validators freeze most of it
An arithmetic overflow in a shared math library let an attacker mint value from almost nothing. What happened next tested whether a blockchain can claw stolen funds back.
On 22 May 2025, at roughly 10:30 UTC, Cetus Protocol — the largest decentralized exchange and liquidity provider on the Sui blockchain — was drained of digital assets worth about $223 million, per SecurityWeek. Elliptic, which traced the funds, put the loss above $200 million and noted some estimates reached $260 million before token prices collapsed. It was the second-largest crypto theft of 2025, behind only the $1.46 billion Bybit hack in February, per Elliptic.
The attacker did not steal a private key or phish an employee. According to analyses of the incident, they exploited an arithmetic overflow bug in an open-source math library that Cetus used to price its liquidity pools. By feeding the contract an extreme value and using spoofed, near-worthless tokens, they tricked the pools into miscalculating balances — depositing a token or two and withdrawing genuine reserves across repeated iterations.
The freeze that split opinion
Within hours, Sui validators coordinated to blacklist the attacker's addresses, freezing roughly $162 million of the loot before it could leave the network, per SecurityWeek. By then the attacker had already swapped USDT for USDC and bridged part of the funds to Ethereum, converting them to ETH through a DEX aggregator, Elliptic found.
The freeze worked, but it unsettled some observers, because it showed that a nominally permissionless chain's validators could collectively censor transactions. The tension between clawing back user funds and preserving neutrality became the defining question of the incident.
Recovery, and the questions it leaves
On 29 May, Sui validators passed a governance vote to return the frozen $162 million to victims — 90.9% in favor, 1.5% abstaining and 7.2% not participating — with the funds moved to a multisig wallet and held in trust, per Cointelegraph. Combined with Cetus's treasury and an emergency loan from the Sui Foundation, the protocol said full recovery for affected users was possible. Cetus also offered the attacker a roughly $6 million bounty for returning the rest, per SecurityWeek.
Cetus restarted its upgraded contracts in the weeks that followed. For users, the episode is a blunt reminder that 'audited' is not 'unbreakable,' and that one shared library can carry risk into every protocol that imports it.
- Audited and blue-chip does not mean risk-free: a bug in one shared dependency can drain many pools at once.
- Concentrating funds in a single venue concentrates your exposure to its worst day — spread size across protocols.
- Recovery here hinged on a rare validator freeze and a foundation loan; never assume an exploit will be reversible.
- After any big hack, impostor 'refund' and 'recovery' sites appear fast — act only on official, signed announcements.
— Sources: [Elliptic](https://www.elliptic.co/blog/cetus-protocol-hacked-for-more-than-200-million) · [SecurityWeek](https://www.securityweek.com/223-million-stolen-in-cetus-protocol-hack/) · [Cointelegraph](https://cointelegraph.com/news/sui-passes-governance-vote-to-recover-162m-cetus-funds)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING