Recommended Free Tools
On May 22, 2025, an attacker exploited Cetus Protocol, a decentralized exchange on the Sui blockchain, draining assets worth about $223 million from its concentrated-liquidity pools. Sui validators and ecosystem participants prevented further movement of roughly $162 million in attacker-linked assets on Sui; Cetus later announced a recovery plan that combined those assets with a loan, treasury funds and CETUS-token compensation. The incident was a smart-contract exploit—not evidence that the Sui blockchain itself was hacked.
What Cetus is—and what the exploit affected
Cetus is a decentralized exchange (DEX) and liquidity protocol on Sui. Like other automated market makers, it lets users trade against token pools rather than matching each trade with a buyer or seller in a traditional order book. People who deposit assets into those pools are liquidity providers; they may earn trading fees, but they also take on smart-contract and market risks.
Cetus used concentrated-liquidity pools, where liquidity providers can choose price ranges in which their assets are active. Concentrating liquidity can make capital more efficient, but it also makes the pool’s calculations and edge cases more complex. The exploit targeted those calculations. It did not mean every Sui transaction or every Sui application was affected.
CETUS is Cetus’s token; it is distinct from both the protocol and the Sui blockchain. A contemporaneous BleepingComputer report described Cetus as Sui’s largest liquidity provider and cited more than $57 billion in cumulative trading volume and over 15 million accounts as of May 2025. Those are historical reported platform metrics, not current figures (BleepingComputer).
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
What happened on May 22, 2025
Elliptic and Blockscope placed the start of the exploit at about 10:30 UTC. The attacker interacted with Cetus pools, drained assets, and moved some funds through swaps and cross-chain bridges. Cetus paused affected contracts and trading activity as the response unfolded. Sui validators and ecosystem participants then coordinated to stop further movement of a large amount of attacker-linked assets that remained on Sui (Elliptic; Blockscope; The Block).
How the exploit worked
The short version
The attacker supplied carefully chosen token inputs and liquidity-range parameters that made Cetus’s pool math accept an abnormally large liquidity position relative to the real assets supplied. That oversized position could then be used to withdraw valuable pool reserves. In simplified terms, the accounting treated a position as much larger than its collateral justified.
What technical analyses identified
Technical reporting connected the exploit to concentrated-liquidity calculations, extreme or manipulated parameter values, and a weakness in validation of numerical values. Cointelegraph’s coverage of Dedaub’s analysis described a flaw involving a most-significant-bit check that allowed liquidity parameters to be manipulated by orders of magnitude. Cetus later attributed the incident to a vulnerability in an open-source library used by its concentrated-liquidity market maker (Cointelegraph’s Dedaub coverage; Cetus’s recovery announcement).
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
Some security analyses described the transaction sequence as involving flash-swap or flash-loan-style capital, narrow tick ranges, and manipulated liquidity calculations. That description should not be mistaken for a claim that a conventional lender caused the exploit: temporary capital was part of the reported transaction mechanics, while the vulnerability was in how pool liquidity was calculated and validated (SlowMist).
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Calling this simply an “oracle attack” obscures the stronger root-cause description supported by the technical reporting: a smart-contract arithmetic and liquidity-accounting exploit. Price and pool-balance manipulation were part of the attack’s effects, but the cited analyses point to faulty handling of concentrated-liquidity parameters rather than an established standalone oracle failure.
How much was taken, and where did the assets go?
The commonly reported figure is approximately $223 million, not a precise cash tally. The drained assets included a basket of tokens, and their prices moved sharply during and after the attack. Elliptic estimated the combined value at more than $200 million and noted that falling token prices meant the attacker was unlikely to realize the full nominal amount. Estimates vary with valuation time and which token movements are counted (Elliptic; BleepingComputer).
Rank #3
- Unparalleled Security: Protect your assets with EAL 6+ Secure Element, offering robust defense and complete transparency
- Simple & Secure Interface: Manage your digital assets easily with a clear OLED screen for secure on-device confirmations
- Supports 1000s of Coins & Tokens: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet
- Effortless Asset Management: Monitor and transact seamlessly with Trezor Suite, our intuitive desktop and mobile app
- Enhanced Backup Solution: Multi-share Backup eliminates single points of failure for secure cold wallet recovery
Blockchain analyses tracked some assets through swaps and bridges. Elliptic reported that some USDT was swapped into USDC and that USDC was bridged from Sui to Ethereum. SlowMist described subsequent conversion into ETH. More than $60 million was reported as moved across chains in technical analyses, but that figure depends on the valuation and movements counted; it does not mean all funds were successfully hidden or permanently beyond recovery (Elliptic; SlowMist; Blockscope).
What the $162 million freeze meant
Blockscope estimated that about $162 million in attacker-linked assets on Sui was prevented from moving further. “Frozen” is useful shorthand, but it does not mean Sui broadly rolled back its blockchain. The intervention concerned designated assets and addresses on Sui. It could not by itself retrieve funds already bridged to Ethereum or another network.
According to Cetus, validators and ecosystem participants quarantined the assets, and a governance process authorized their recovery. The response demonstrated the benefit of emergency coordination: a large share of the on-chain value was kept from moving. It also raised a difficult question for proof-of-stake networks: how much validator coordination to block transactions is compatible with censorship resistance and predictable rules? The intervention was neither a general chain rollback nor a cost-free technical choice.
Rank #4
- UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
- EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
- ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
- SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
- EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app
What Cetus announced for recovery and relaunch
In its June 7, 2025 announcement, Cetus said its plan drew on several different kinds of support. These were first-party claims about the proposed recovery, not proof that every affected user received immediate repayment in the original asset.
| Recovery component | What Cetus announced | What it means for affected users |
|---|---|---|
| Quarantined assets | Recovery of assets frozen on Sui following validator and community action. | Recovered pool value, but not necessarily a direct cash reimbursement to each user. |
| Sui Foundation loan | A 30 million USDC recovery loan. | Borrowed stablecoin support; a loan is not the same as a grant or recovered original tokens. |
| Cetus treasury | Approximately $7 million in available treasury cash reserves. | Protocol funds committed to the recovery plan. |
| Pool restoration | Initial affected-pool recovery rates of 85% to 99%, depending on the pool. | Liquidity restoration varied by pool rather than guaranteeing a uniform percentage to every user. |
| CETUS compensation | 15% of CETUS supply allocated for compensation: 5% immediately claimable and 10% released monthly over 12 months. | Token compensation is exposed to price changes and delayed release; it is not equivalent to immediate repayment in the original assets. |
Cetus announced a relaunch for 3:00 UTC on June 8, 2025, after describing vulnerability fixes, asset recovery, pool replenishment, and audits of relevant changes. Its Q2 report later described additional post-incident security work. These operational and security statements come from Cetus; an audit or relaunch is not a guarantee that a protocol cannot be exploited again (Cetus recovery and relaunch announcement; Cetus Q2 2025 report).
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Were users made whole?
The announced plan combined recovered assets, treasury reserves, borrowed USDC, restored pool liquidity, and CETUS-token compensation. Those forms of value differ in liquidity, timing, denomination, and market risk. The available announcements establish the plan and its stated pool recovery ranges, but do not independently establish that every affected user ultimately received full reimbursement in cash or in the original assets.
Best Value
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
For a particular position, the relevant questions are whether it was in an affected pool, what snapshot or recovery rules applied, and what portion of any shortfall was allocated as pool value versus token compensation. A token allocation that vests over time can fall or rise in market value, so its announced percentage does not by itself establish the final value a user received.
What the incident says about audits and DeFi risk
The incident shows why an audit cannot be treated as a guarantee. Concentrated-liquidity contracts must handle tick boundaries, rounding, overflow, and extreme inputs correctly; a weakness in a shared library can affect every protocol component that relies on it. A safe-by-design programming language also cannot automatically validate the financial logic built with it.
The available accounts establish that a vulnerability was identified and that Cetus announced additional security work, but they do not establish the complete audit history, precisely which reviews covered the vulnerable code, or why earlier safeguards did not catch the relevant edge case. It would therefore be unsupported to say that a particular audit failed or that an audit proved the deployed system safe.
Cross-chain bridges and token swaps gave the attacker routes to move and convert assets, while public ledgers and blockchain analytics made those movements traceable. Stablecoin controls can sometimes help contain funds, but only where the issuer, token, and network support that action. Neither tracing nor freezing guarantees recovery.
Free tools Windows power users keep installed
One-click scans. No signup required.
What Sui users and liquidity providers should take away
- Protocol risk remains even after a relaunch. A patch, audit, or restored pool is evidence of work performed, not a promise of immunity from future exploits.
- Pool liquidity is not a bank deposit. Depositing into a smart-contract pool exposes assets to contract bugs, market swings, and recovery rules.
- Emergency intervention has trade-offs. It can preserve value in a crisis while giving validators and governance participants consequential power over transactions and assets.
- Compensation terms matter. Check the asset, amount, eligibility snapshot, claim process, and release schedule; a token award may not match an immediate return of the assets originally deposited.
- Verify recovery information at the source. Use official Cetus announcements and carefully verify the domain before connecting a wallet. Do not connect a wallet to recovery or compensation links sent in unsolicited messages or social-media replies.
The incident belongs to May 2025, and Cetus announced its relaunch and recovery plan that June. The available sources do not establish the protocol’s present-day safety, current compensation completion, or final user-by-user settlement status.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




