Cetus suffered an attack resulting in a loss of $230 million, raising alarm bells for the security of the SUI ecosystem.

Cetus Attacked, Loss Exceeds $230 Million

On May 22, the SUI ecosystem liquidity provider Cetus allegedly suffered an attack, with multiple trading pairs experiencing significant declines and the liquidity pool depth sharply decreasing, with estimated losses exceeding $230 million. Cetus subsequently issued a statement saying that it has suspended the smart contract and is investigating the incident.

Slow Fog: Cetus stolen 230 million USD, analysis of attack methods and fund transfer situation

The security team conducted an in-depth analysis of the attack, revealing the specific methods used by the attackers.

Attack Analysis

Attackers exploited system vulnerabilities by carefully constructing parameters to achieve operations that exchanged a very small amount of tokens for a huge amount of liquidity. The specific steps are as follows:

  1. Borrowing a large amount of haSUI through flash loans caused the pool price to plummet by 99.90%.

  2. Open liquidity positions in a very narrow price range, with a range width of only 1.00496621%.

  3. Declares to add a huge amount of liquidity, but actually pays only 1 token A. This is the core of the attack, exploiting the overflow detection bypass vulnerability in the checked_shlw function of get_delta_a.

  4. The system has a serious deviation when calculating the required haSUI amount, leading to a misjudgment that allows attackers to exchange a minimal amount of Tokens for a large quantity of liquidity assets.

  5. Finally, remove liquidity to obtain huge token profits and complete the attack.

Slow Mist: Cetus was hacked for $230 million, analysis of attack methods and fund transfer situations

Slow Fog: Cetus was stolen 230 million USD, analyzing the attack method and fund transfer situation

Slow Mist: Cetus was hacked for $230 million, analysis of the attack method and fund transfer situation

Project Party Fix

After the attack, Cetus quickly released a patch. The main fix addressed the error mask and judgment conditions in the checked_shlw function, ensuring that it can correctly detect situations that may lead to overflow.

Slow Mist: Cetus was hacked for 230 million USD, analyzing the attack method and fund transfer situation

Slow Fog: Cetus was hacked for $230 million, analyzing the attack methods and fund transfer situation

Capital Flow Analysis

Attackers profited approximately $230 million, including various assets such as SUI, vSUI, and USDC. Some funds were transferred to EVM addresses via cross-chain bridges. Approximately $10 million in assets were deposited into Suilend, and 24 million SUI were transferred to a new address and have not yet been withdrawn.

Fortunately, the SUI Foundation and other relevant parties have successfully frozen approximately $162 million of the stolen funds on the SUI chain.

On the EVM chain, the attacker exchanged part of the funds for ETH and transferred 20,000 ETH to a new address. Currently, the balance of that address on Ethereum is 3,244 ETH.

Slow Mist: Cetus was hacked for 230 million USD, analyzing the attack method and fund transfer situation

Slow Fog: Cetus was hacked for $230 million, analysis of attack methods and fund transfer situation

Slow Fog: Cetus was hacked for $230 million, analysis of attack methods and fund transfer situation

Slow Fog: Cetus was hacked for $230 million, analyzing the attack method and fund transfer situation

Slow Fog: Cetus was hacked for $230 million, analyzing the attack method and fund transfer situation

Slow Fog: Cetus was hacked for 230 million USD, analysis of attack methods and fund transfer situation

Slow Fog: Cetus was hacked for $230 million, analyzing the attack method and fund transfer situation

Slow Mist: Cetus was hacked for $230 million, analyzing the attack methods and fund transfer situation

Slow Mist: Cetus was hacked for $230 million, analyzing the attack method and fund transfer situation

Slow Mist: Cetus was hacked for $230 million, analyzing the attack methods and fund transfer situation

Slow Mist: Cetus was hacked for $230 million, analyzing the attack method and fund transfer situation

Slow Fog: Cetus was hacked for $230 million, analyzing the attack methods and fund transfer situation

Slow Mist: Cetus was hacked for 230 million USD, analyzing the attack methods and fund transfer situation

Slow Fog: Cetus was hacked for $230 million, analyzing the attack method and fund transfer situation

Slow Mist: Cetus was hacked for $230 million, analyzing the attack methods and fund transfer situation

Summary

This attack fully demonstrates the power of mathematical overflow vulnerabilities. The attacker achieved substantial profits by precisely calculating and selecting parameters, exploiting function defects in the smart contract. This serves as a reminder to developers that they must rigorously validate all boundary conditions of mathematical functions during contract development to prevent similar attacks.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Share
Comment
0/400
GateUser-a6cc3225vip
· 12h ago
It's all about showing off, but in reality, the money has already gone into their pockets. You guys have hackers.
View OriginalReply0
AirdropHunterXiaovip
· 12h ago
This day is so disgusting. Why do these contracts always have problems?
View OriginalReply0
WalletAnxietyPatientvip
· 12h ago
The Sui ecosystem has collapsed now, right?
View OriginalReply0
LiquidityWizardvip
· 12h ago
It's a big deal, Sui, everything has been rolled up.
View OriginalReply0
NotGonnaMakeItvip
· 13h ago
Another billion-dollar project is doomed~
View OriginalReply0
TokenEconomistvip
· 13h ago
actually, this is classic market manipulation via flash loan arbitrage... textbook price manipulation dynamics here
Reply0
FalseProfitProphetvip
· 13h ago
smart contracts洞太频了 傻掉
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)