In May 2025 attackers exploited weaknesses in the smart contracts of Cetus Protocol, the largest decentralised exchange in the Sui ecosystem, using spoof tokens to manipulate price calculations and drain liquidity pools.
There Was No Intrusion
Nothing was accessed without authorisation. No credential was stolen, no server compromised, no employee deceived. The attacker submitted transactions that the contract accepted, evaluated and executed exactly as its published code specified.
The loss arose because the specification and the intent diverged. That is a category this database has almost no other examples of: a failure entirely inside the logic, where every participant behaved as the system permitted.
Which Breaks The Vocabulary
Terms this desk uses constantly — intrusion, unauthorised access, dwell time, containment, eviction — presuppose a boundary and someone crossing it. None of them apply.
The case card for this file records "Not applicable" more than any other in the corpus, and that is the honest answer rather than a gap in reporting. Even the word "exploit" is doing unusual work: what was exploited was a mistaken assumption, not a defect in an implementation.
And It Removes The Response Options
Elsewhere in this corpus an organisation that detects an intrusion can disconnect, revoke, rebuild. Systems designed to execute autonomously and resist intervention have deliberately given that up — immutability and censorship resistance are the product, and they are indistinguishable from an inability to stop a loss in progress.
Nothing about that is hidden. It is the stated design. But it means the security model has to be complete before deployment, in a way that no other software in this database is expected to be.
Compiled from published incident summaries, listed below. Amounts and recovery outcomes vary between accounts and we do not state a figure. The mechanism is as reported. Corrections: corrections@forensicpost.com.