Attackers exploited a crucial overflow flaw in Cetus Protocol’s automated market maker logic, which led to $223 million in person losses, in response to a autopsy by Dedaub.
“This incident represents one of the vital vital DeFi exploits in current historical past, attributable to a refined however crucial flaw in “overflow” safety,” blockchain safety agency Dedaub mentioned in its report.
Dedaub defined that the flaw concerned an “overflow” within the math utilized by Cetus’s automated market maker, the place a miswritten situation didn’t correctly deal with probably the most vital bits of huge numerical inputs and “didn’t produce the supposed end result.”
As a substitute of rejecting outsized values, the system truncated them, inflicting the output to look a lot smaller than it ought to have.
This allowed the attacker to deposit only a single token whereas the protocol mistakenly credited them with an unlimited liquidity place. They then used that place to withdraw giant quantities of actual belongings from the swimming pools.
In response to Dedaub, the same vulnerability had been flagged in early 2023 by blockchain safety agency Ottersec throughout an audit of the protocol’s codebase when it was deployed on Aptos.
Nonetheless, after the code was later ported to the Sui community, the underlying concern nonetheless remained. Though builders tried to implement safeguards, the overflow verify was flawed, permitting the identical sort of exploit to slide via unnoticed.
“This incident reveals why edge circumstances in DeFi can’t be ignored,” Dedaub warned, including that complicated math in decentralized finance wants cautious evaluate and testing. It urged builders to confirm overflow safety manually, particularly when utilizing giant numbers or superior math.
Cetus exploit triggered sell-off
Cetus, a number one DEX on the SUI community, was hacked within the early hours of Could 22, triggering one of many largest losses within the Sui ecosystem thus far. Preliminary investigations claimed the incident stemmed from an “oracle bug.”.
The exploit led to over $223 million in losses throughout varied liquidity swimming pools, sparking a broad sell-off in associated tokens, together with SUI and CETUS, which dropped over 40% within the hours after the breach. Memecoins and smaller market cap tokens native to the community noticed even steeper losses, with some plunging by over 90%.
In response, the Sui Basis coordinated with validators to freeze round $163 million of the stolen funds. Cetus has additionally introduced a $5 million bounty for data that identifies these accountable.


