$223M Vanishes from Sui’s Largest DEX — Here’s How the Cetus Hack Happened

Spoof tokens and manipulated price logic allowed a hacker to drain over $223M from Cetus, Sui’s largest DEX.

Spoof tokens and manipulated price logic allowed a hacker to drain over $223M from Cetus, Sui’s largest DEX.

Share this crypto insight on your favorite social media platform

Key Points:

  • Cetus, Sui’s largest DEX, was exploited for over $223M using spoof tokens.
  • The attacker drained SUI and USDC by manipulating pool logic, bridged the funds to Ethereum, and swapped $58.3M USDC for 21,938 ETH.
  • Cetus fell 30% and SUI dropped over 5% according to CoinMarketCap.

Cetus Protocol, the largest decentralized exchange (DEX) on the Sui (SUI) network, representing approximately 88% of total DEX volume on SUI, suffered a major exploit on May 22, resulting in the loss of over $223 million from its liquidity pools. Cetus responded by pausing its smart contracts and is working with the Sui Foundation to recover the funds. The team claims to have frozen $162 million of the stolen amount. Other major DEXs like Bluefin and Momentum temporarily suspended operations during the exploit, but have since resumed normal activity.

Cetus’ X post on the hack.
AD 4nXfCFxDOTTxp0mroAuYNOoTRH4dRZtLnX tqeXsP8pWqUQPcLowchoF 8RhdcoaHSmROpD3J4Y3qzULEBSmurq8GVhB yjaS7p6TI0VJAQG5BU6Jje8CXSAk8qTuwJRbbDJFpdAL2g?key=iifvtRTDrGIVuzGciA8E Q
Source: DefiLlama

The attacker used spoof tokens to manipulate price curves and reserve logic, enabling the withdrawal of SUI and USDC. The exploit wallet, according to Lookonchain’s X post, has converted stolen assets to USDC and bridged to Ethereum, where they’ve already used $58.3M USDC to buy 21,938 ETH at $2,658 each.

How the $223M Cetus Hack Was Pulled Off — Explained Simply

The recent hack on Cetus, the biggest decentralized exchange (DEX) on the Sui network, wasn’t your typical code exploit. Instead, the attacker used smart manipulation of token pricing logic inside the DEX to drain real funds, mainly SUI and USDC.

Here’s how they did it, step by step:

1. They Created a Fake Token

The hacker created tokens like AXAI, made to look real but worthless. These tokens were under the hacker’s full control, meaning they held the maximum supply. The images below were taken from Sui scan.

AD 4nXc7fUT8compprfgg0pQoFBk skPZxGGXb3Bejj0OFL8 U7sS6GFPX7 qEgZVKhtJliVCef daSpDiSETdFxcvdgJkfJIzYy7aIp6Z5SHVEouQ8aHmN5Y3DXT1NCSBmiJjXijHU GA?key=iifvtRTDrGIVuzGciA8E Q
AXAI Token was created 4 months ago. (Image source: suiscan.xyz)
AD 4nXfDN1eGW0TAPTIoS6oN 1Qrq6m5xjM2kpsUVtsVUMmUoq0Oii22XC21zE MGqDz17 sSXCyNpKF1MVLnb9CYc7meTQ0LCjrzIKxBTeWo EfargybfJunSH0XeCmBkuCLMEx0eCaQ?key=iifvtRTDrGIVuzGciA8E Q
The wallet linked to the hack held over 89% of the supply. (Image source: suiscan.xyz)

2. They Built a Liquidity Pool

On Cetus, anyone can create a trading pool. The hacker made a pool with:

  • 1,000,000 AXAI (worthless)
  • 1 SUI (real money)

To the smart contract, this meant 1 AXAI = 0.000001 SUI, even though AXAI had no actual value.

3. They Manipulated the Price

By adding or swapping tiny amounts of AXAI, they tricked the DEX into thinking AXAI was worth more. This is because DEXs like Cetus use math, not real-world prices, to determine value. The system has no idea AXAI is fake, it just sees numbers.

4. They Swapped Fake for Real

Now that the price of AXAI looked valuable to the DEX, the attacker swapped large amounts of AXAI for real SUI from the liquidity pool. No real buyer was involved — the DEX itself gave away the SUI, thinking it was a fair trade.

AD 4nXfFqKFphIShCAnHJaDbQFMi55jVrN s234uBIibZJRQ7a4n1880yXubucupmx6pNq2RhA8qnnji3MFWwJcaiHf l wrI2cAEaVsfQHVpnfSAWwMgyUFuqoummsaQRmfV7YcjeFIWw?key=iifvtRTDrGIVuzGciA8E Q
The hacker created a token called “SPAM”. (Image source: suiscan.xyz)

5. They Repeated the Process

They created multiple spoof tokens and pools, doing the same trick over and over. Each time, they pulled out more SUI and USDC, eventually draining over $220 million worth of tokens.

AD 4nXfMXWCfO4EHomKNY6mvzFDRcgHcAcX AyxggkztvIgbHX8AL3WVbhIsIL7fGwtiqNo7Uys PRiHxil61fpYxpicd6oRBYJdmuqGKUpOaItDxaZcjP9zRVGnqAvMkYXReYGa6K7Cwg?key=iifvtRTDrGIVuzGciA8E Q
Multiple such transactions took place. (Image source: suiscan.xyz)

HackenProof’ – bug bounty and crowdsourced audit platforms – CTO posted:

The Cetus hacker also used Hyperliquid as part of the laundering process, sending stolen funds through the DEX to swap assets and obscure the money trail after bridging from Sui to Ethereum.

AD 4nXe6G3EpQueMHXvvzrVtvMLUxvDzY0pav Id2z6sjJkRg6RWrUw Fdjp rV7qxm1 w8ge44QK4wKaYIS8Uj9x3beJfqqUBijoFXZAg78z2bLM OITstBvRE rl6e1eY1ApGRuyIC0Q?key=iifvtRTDrGIVuzGciA8E Q
Source: Arkham Intelligence

The incident triggered immediate price drops:

  • Sui-based tokens such as BULLA and MOJO fell by over 90%

Moreover, a rapid collapse in token prices was observed on Cetus, indicating a liquidity crisis and loss of trader confidence following the recent exploit.

AD 4nXebL6eddRO91qaqRjG0IiWtheZoCo5AHbnXS5rozh36h7Z0zQ0Bk xNvTqgSFWhlq1FWIFJTm4KFTt81q eMYrhd srkT79FJsc4Osh2VsrRpJTPSh41eqDDXavExeUB0TUnWo1Fg?key=iifvtRTDrGIVuzGciA8E Q
Source: DEX Screener

Industry Voices Weigh In:

Binance founder CZ stated that his team has reached out to assist.

Disclaimer

All content provided on Times Crypto is for informational purposes only and does not constitute financial or trading advice. Trading and investing involve risk and may result in financial loss. We strongly recommend consulting a licensed financial advisor before making any investment decisions.