Free tools Windows power users keep installed
One-click scans. No signup required.
On May 22, 2025, attackers exploited an arithmetic flaw in Cetus Protocol’s concentrated-liquidity smart contracts on Sui. Cetus estimated that roughly $223 million in digital assets had been extracted. Validators and ecosystem participants secured about $162 million that was still on Sui, while approximately $60 million had reportedly moved off-chain, including assets bridged to Ethereum.
This was not a centralized exchange database breach or a stolen private-key incident. The attacker manipulated liquidity accounting so the contracts recognized an invalid, vastly oversized position and released genuine pool reserves. A later Sui governance vote moved the frozen assets to a recovery multisignature wallet, creating a major debate about emergency intervention on a supposedly permissionless blockchain.
What is Cetus Protocol?
Cetus is a decentralized exchange and liquidity protocol in the Sui ecosystem. It supports token swaps, liquidity pools, aggregation, vaults and concentrated-liquidity markets; its current site also lists Aptos support. In a concentrated-liquidity market maker, providers select price ranges for their funds instead of supplying liquidity across every possible price.
That design can improve capital efficiency, but it makes the mathematics around ticks, rounding, signed values and liquidity amounts unusually sensitive to edge cases. Cetus’s current services are described at cetus.zone. A live website does not, by itself, establish the final status of historical reimbursement claims.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
What happened on May 22, 2025?
- May 22: Cetus detected abnormal activity, paused affected contracts and began investigating.
- May 23–28: Investigators and ecosystem participants traced the attacker’s transactions, estimated the losses and sought to secure assets remaining on Sui.
- May 27–30: Sui’s governance process considered an intervention for frozen funds. Sui’s official response was published on May 30, while SecurityWeek’s incident account is dated May 28.
- After the vote: The secured assets were transferred to a multisignature wallet for recovery and distribution planning.
Early contemporaneous reports cited figures near $260 million. Cetus’s principal public estimate settled near $223 million, so the higher number should be treated as an early estimate rather than the final incident total.
How the smart-contract exploit worked
The core failure was in liquidity-calculation and overflow-checking logic. Galaxy Research described an integer overflow caused by a flawed overflow check; SecurityWeek described manipulation of tick and liquidity mechanisms in a vulnerable open-source library. The issue was not simply that the attacker traded against a bad price.
- The attacker reportedly used a flash-loan-style strategy to obtain temporary capital.
- They supplied manipulated or effectively worthless token inputs to a concentrated-liquidity pool.
- A boundary calculation accepted an extreme value instead of rejecting it as invalid. The arithmetic overflow made the computed liquidity position appear enormously larger than the economic value supplied.
- That artificial position entitled the attacker to withdraw real reserves, including SUI and stablecoins.
- The process was repeated across multiple transactions or pools before the affected contracts were paused.
In plain English, the contracts lost track of how much liquidity the attacker actually owned. Once the accounting error inflated the position, normal withdrawal logic released assets belonging to other liquidity providers.
Why concentrated-liquidity math is difficult to secure
- Tick boundaries can change which formulas and token amounts apply.
- Rounding, underflow and overflow can produce radically different results at extreme values.
- Signed-versus-unsigned conversions can turn a negative or invalid intermediate result into a very large positive number.
- Third-party libraries can introduce vulnerabilities even when a protocol’s own code appears carefully reviewed.
Audits are not guarantees. The relevant questions are whether the vulnerable dependency and extreme-value paths were in scope, and whether the audit method included formal reasoning, fuzzing and property-based tests for boundary conditions.
Recommended Free Tools
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
How much was stolen?
The figures describe different stages of the incident, not three competing totals.
| Figure | What it represents | Qualification |
|---|---|---|
| Approximately $223 million | Cetus’s principal estimate of assets exploited | Gross value at incident-time prices, not necessarily the attacker’s permanent gain |
| Approximately $162 million | Assets frozen or otherwise secured on Sui | Secured from further movement; “frozen” does not itself mean users had already been repaid |
| Approximately $60 million | Assets reportedly moved away from Sui | Included funds bridged to Ethereum; moved does not mean permanently unrecoverable |
| About $260 million | Higher early media estimate | Preliminary figure, superseded by the later $223 million estimate |
Galaxy reported an incident-time mix that included approximately 12.9 million SUI, valued at about $54 million then, around $60 million in USDC, and roughly $4.9 million in haSUI, along with other Sui-based tokens. Those dollar values were calculated near the attack date and are not current market valuations.
How the attacker moved the assets
SecurityWeek reported that the attacker initially swapped USDT into USDC, then bridged assets to Ethereum and converted portions into other tokens. This created three distinct recovery situations:
- Assets still on Sui: Validators and ecosystem participants could identify and restrict movement under the emergency response.
- Assets bridged to Ethereum: They could be traced publicly, but recovery required cooperation from other networks, custodians or counterparties.
- Assets swapped or converted: A transaction trail may remain visible without making the resulting funds legally or technically recoverable.
How Sui secured approximately $162 million
Cetus first paused affected contracts. That was a protocol-level emergency control, not the same thing as a blockchain rollback. Sui validators then helped freeze or secure attacker-controlled assets that remained on Sui. A subsequent governance-approved transaction transferred those assets into a recovery multisignature wallet associated with Cetus, the Sui Foundation and security firm OtterSec.
Rank #3
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
Galaxy reported that the vote passed with 99 votes in favor, two against and two abstentions, representing approximately 92% of total stake. The intervention did not erase the attacker’s transactions or rewind the entire Sui chain.
The decentralization controversy
Supporters argued that coordinated action protected a large majority of user funds and stopped additional movement. Critics saw a precedent for validators to censor transactions or reassign assets in an emergency. Both observations can be true: the network remained operational, but its practical governance allowed extraordinary intervention.
The episode separates two ideas often treated as identical. A protocol may be permissionless for ordinary users while its validator set retains the ability to coordinate under exceptional conditions. A multisignature recovery wallet also replaces one type of risk with others, including signer availability, key security and the possibility of disputes over distribution.
What happened to the remaining approximately $60 million?
The off-Sui portion was reportedly bridged primarily to Ethereum before the validator intervention. Cross-chain movement complicates recovery because a Sui validator cannot directly freeze an asset on Ethereum. Tracing can identify destinations and counterparties, but recovery may depend on whether the funds reach a regulated custodian, remain immobilized, or are exchanged into assets that cannot be recalled.
Rank #4
- UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
- EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
- ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
- SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
- EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app
Token prices also fluctuate. A reimbursement calculated in dollars may not return the same tokens, and a stablecoin can trade away from its intended peg during a liquidity crisis.
What was the $6 million white-hat offer?
Cetus offered the attacker a $6 million bounty in exchange for returning the remaining assets. That was a negotiation proposal, not evidence that the attacker accepted it or that the funds were returned under the offer. Public reporting cited the offer but did not establish an acceptance and settlement that would account for every dollar.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Were affected users fully reimbursed?
Cetus announced a plan intended to make affected users whole, using the secured assets, treasury resources and financial support from the Sui Foundation. SecurityWeek described 100% recovery as possible under that plan. Galaxy reported that the foundation extended a loan to address a shortfall, although the loan’s maturity and interest terms were not stated.
The careful conclusion is narrower: a recovery and reimbursement plan was announced, but the available reporting does not provide a sufficiently clear, final primary-source distribution accounting to declare that every affected user was definitively repaid. “$162 million frozen” is not synonymous with “$162 million distributed,” and “$60 million moved off Sui” is not synonymous with “$60 million permanently lost.”
Best Value
- Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
- Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
- See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
- Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
- Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
Security lessons for DeFi developers
Prove arithmetic assumptions
Overflow checks must be mathematically correct at the boundaries, not merely tested with ordinary values. Use property-based tests, fuzzing and explicit invariants for maximum ticks, liquidity amounts, token decimals and conversion paths.
Audit dependencies and integration code
Open-source libraries create supply-chain risk. Reviews should cover the exact dependency versions, wrappers and assumptions used in production, not just the protocol’s original code.
Design emergency controls before an incident
Pause mechanisms, clear authority boundaries, rate limits and transparent recovery procedures can reduce losses. They also need governance safeguards so emergency powers do not become indefinite censorship tools.
Monitor cross-chain flows
Real-time alerts for unusual minting, liquidity changes, bridge transfers and rapid asset conversion can shorten the window between exploitation and containment.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →What users should do
- Do not connect a wallet to an unofficial “Cetus recovery” page or sign a transaction promising to unlock hack-related funds.
- Verify the official domain and inspect every transaction, allowance and destination before signing.
- Do not assume that a token with a familiar ticker such as USDC, USDT, SUI or haSUI is authentic; verify its contract address.
- Do not re-enter an affected pool merely because the front end is live.
- Read the protocol’s current risk disclosures. Cetus’s terms and disclaimer state that users are responsible for wallet security, transaction verification and smart-contract risk, and do not guarantee uninterrupted service, accurate quotes or protection from vulnerabilities.
Why this incident matters
The Cetus exploit was simultaneously a major smart-contract security failure and a demonstration of how recovery works in practice. The arithmetic bug drained pools without stealing a private key; validators and a governance vote then secured much of what remained, while institutional support was proposed to cover the gap. The headline $223 million describes the gross amount exploited. The net loss, final distribution and ultimate reimbursement status require keeping the frozen, bridged and repaid amounts separate.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




