Skip to content
← Back to newsCetus Hack Exposed: Security Firm Releases Detailed Post-Mortem Report
Security

Cetus Hack Exposed: Security Firm Releases Detailed Post-Mortem Report

By ToTo BugelmanNewcomer0 rep· 5/26/2025

Blockchain security firm Dedaub has released a comprehensive post-mortem report on the recent Cetus hack. This incident, which compromised the decentralized finance (DeFi) protocol, has raised serious concerns about security vulnerabilities in the blockchain space.

 

Key Takeaways

  • The Cetus hack resulted in losses exceeding $223 million.

  • A flaw in the liquidity parameters of the automated market maker (AMM) was exploited.

  • The incident has sparked discussions on the need for improved security measures in DeFi.

  • Mixed reactions emerged regarding the freezing of stolen assets by Sui network validators.

 

Understanding The Cetus Hack

The Cetus protocol, operating on the Sui blockchain, suffered a major security breach on May 22, leading to substantial financial losses. Dedaub's report identified the root cause as an exploit of the liquidity parameters used by the Cetus AMM, which went undetected due to a flaw in the most significant bits (MSB) check.

 

The flawed MSB check: Dedaub

 

The attackers manipulated the liquidity parameters, allowing them to create large positions with minimal input. This loophole enabled them to drain pools containing hundreds of millions of dollars worth of tokens in a matter of minutes.

 

Immediate Response And Recovery Efforts

Following the hack, the Cetus team took swift action to pause the affected smart contract and initiated a recovery plan. The Sui Foundation also intervened, with validators freezing approximately $163 million of the stolen assets on the same day as the attack. This response, however, drew criticism from decentralization advocates who argued that it undermined the principles of a decentralized network.

 

Broader Implications For The DeFi Ecosystem

The Cetus hack has highlighted the ongoing challenges in the DeFi sector, particularly regarding security vulnerabilities. As the industry continues to grow, the need for robust security measures and standardized protocols has become increasingly urgent. Key recommendations include:

  • Enhanced Security Audits: Regular and thorough audits of smart contracts to identify potential vulnerabilities.

  • User Education: Informing users about the risks associated with DeFi platforms and how to protect their assets.

  • Real-Time Monitoring: Implementing tools to monitor transactions and detect unusual activity promptly.

 

Trust Issues And Transparency Concerns

The lack of clear communication from the Cetus team following the hack has fueled speculation about the nature of the incident. While the team initially attributed the losses to a software bug, many experts suspect a coordinated exploit, given the rapid transfer of funds.

The incident has raised questions about the transparency and readiness of DeFi platforms to handle crises effectively. As the community calls for better communication and accountability, the need for a comprehensive recovery plan remains critical.

 

Steve Bowyer

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.