The Sui Foundation has issued a secured loan to decentralized exchange Cetus Protocol in a bid to support its recovery following a $260 million exploit, aiming to fully compensate affected users. The move, announced on May 27, triggered a 27% surge in the CETUS token, signaling renewed investor confidence.
The exploit, which occurred on May 22, targeted Cetus’s pricing mechanism via an oracle manipulation attack involving spoofed tokens. According to CetusProtocol, the attacker siphoned $223 million in total assets, with $61.5 million bridged to Ethereum in USDC. Another $162 million was frozen on the Sui blockchain by network validators, raising concerns over centralization in the Sui ecosystem.
The secured loan provided by the Sui Foundation will be used in conjunction with Cetus’s own treasury assets to specifically cover the bridged USDC losses—funds the protocol was unable to recover on its own. A separate governance vote, scheduled to begin at 1:00 p.m. PT on May 27, will determine whether the frozen $162 million on Sui will be returned to users. As of May 28, Cointelegraph reports that 52.9% of validators have voted in favor of releasing the funds, which would be managed via a multisig trust and redistributed to victims.
Cetus Protocol stated it will begin the recovery process immediately following the vote, regardless of its outcome, with a full implementation plan forthcoming.
The announcement had immediate market implications. CETUS, which had plunged from $0.26 to $0.15 after the exploit, rebounded by 27% following news of the loan, according to trending data on X. SUI, the native token of the Sui blockchain, dropped 14% from $4.19 to $3.62 in the days after the incident, though recent stabilization suggests a positive market reaction to the Foundation’s intervention. The blockchain’s total value locked (TVL) declined from $2.13 billion to $1.92 billion, reflecting broader pressure on the ecosystem, according to crypto.news.
The move underscores the Sui Foundation’s commitment to protecting users and preserving trust across its ecosystem. The combination of emergency funding and community-driven governance presents a hybrid model of crisis management that merges centralized support with decentralized decision-making.
Still, the incident highlights enduring vulnerabilities in decentralized finance infrastructure. Oracle manipulation attacks, such as the one targeting Cetus, accounted for nearly half of all DeFi losses in 2023, according to Halborn. The event also reignites scrutiny of newer chains like Sui, with analysts pointing to potential security gaps and governance concerns.
As the community vote progresses and the recovery plan unfolds, the Sui Foundation’s response may serve as a test case for how emerging blockchain ecosystems handle high-stakes security breaches.