Desk live·
ForensicPost
Cloud/Protocol/File 25-0523

Attackers Drained Cetus Protocol Liquidity Using Spoof Tokens

Attackers drained liquidity from Cetus Protocol by using spoof tokens to manipulate price calculations. No system was breached; the contract was used as written.

Constructed geometry · not a chart of case data
TargetCetus Protocol
ActorUnattributed
D. Kennedy11 min readConfidence: medium2 sources reviewed

In May 2025 attackers exploited weaknesses in the smart contracts of Cetus Protocol, the largest decentralised exchange in the Sui ecosystem, using spoof tokens to manipulate price calculations and drain liquidity pools.

There Was No Intrusion

Nothing was accessed without authorisation. No credential was stolen, no server compromised, no employee deceived. The attacker submitted transactions that the contract accepted, evaluated and executed exactly as its published code specified.

The loss arose because the specification and the intent diverged. That is a category this database has almost no other examples of: a failure entirely inside the logic, where every participant behaved as the system permitted.

Which Breaks The Vocabulary

Terms this desk uses constantly — intrusion, unauthorised access, dwell time, containment, eviction — presuppose a boundary and someone crossing it. None of them apply.

The case card for this file records "Not applicable" more than any other in the corpus, and that is the honest answer rather than a gap in reporting. Even the word "exploit" is doing unusual work: what was exploited was a mistaken assumption, not a defect in an implementation.

And It Removes The Response Options

Elsewhere in this corpus an organisation that detects an intrusion can disconnect, revoke, rebuild. Systems designed to execute autonomously and resist intervention have deliberately given that up — immutability and censorship resistance are the product, and they are indistinguishable from an inability to stop a loss in progress.

Nothing about that is hidden. It is the stated design. But it means the security model has to be complete before deployment, in a way that no other software in this database is expected to be.

How we reported this

Compiled from published incident summaries, listed below. Amounts and recovery outcomes vary between accounts and we do not state a figure. The mechanism is as reported. Corrections: corrections@forensicpost.com.

Sources
  1. Crypto hacks 2025: full list of scams, exchange exploits and DeFi vulnerabilitiesCCN
  2. The evolution of crypto exchange breaches (2011–2025)Forward Security
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary