Cetus Protocol Reboots After $223M Hack With Major Liquidity Restore and Fresh Security Plans

The Cetus Protocol, a decentralized exchange built on Sui and Aptos blockchains, officially resumed operations on Sunday, just weeks after suffering one of the most severe DeFi exploits in May 2025. The relaunch marks a significant recovery milestone for the protocol, which had been forced offline following a $223 million exploit stemming from a vulnerability in a shared math library.

The breach, executed on May 22, allowed a sophisticated attacker to manipulate token values by triggering an integer overflow, inflating a deposit's value into the millions. Though devastating, the attack was quickly met with a partial response — validators on the Sui network froze $162 million of the attacker’s haul, which has since been returned to Cetus.

To restore affected pools, the Cetus team injected a combination of the recovered Sui assets, its $7 million in reserves, and a $30 million USDC loan from the Sui Foundation. The result: a restoration of 85% to 99% of original liquidity for impacted liquidity providers. The remaining shortfall is set to be compensated through CETUS token emissions over the next 12 months, following a linear vesting schedule — contingent on any further recovery efforts from the hacker.

According to a protocol statement, the exploited vulnerability has now been patched, and all impacted pools have been rebalanced. Cetus also performed a comprehensive audit before returning to full functionality. However, the protocol confirmed that tens of millions of dollars are still controlled by the hacker, who has begun obfuscating funds via Tornado Cash and has transferred some assets to Ethereum-compatible wallets.

Despite efforts to reach out with a whitehat bounty, Cetus said the attacker has declined all negotiations. “We remain confident that law enforcement and tracking will lead to eventual recovery,” the team wrote, calling the laundering attempt "futile and traceable."

Blockchain security firm SlowMist, which investigated the incident, revealed the attacker had begun staging the exploit two days in advance and even tested a failed version of the attack before launching the final one. Only Sui-based pools were impacted; the Aptos side of Cetus remained untouched.

Looking ahead, Cetus plans to implement a suite of protocol upgrades, including a revamped security audit cycle, real-time exploit detection infrastructure, and a revised roadmap for future features. A white-hat bounty program is also in the works to help preempt future vulnerabilities.

“The restart is more than just a reboot — it’s a renewed mission,” the team said in a statement.

CETUS, the protocol’s native token, is down roughly 44% since May 21 — the day before the exploit.