Aftermath Perps Hack

Reported loss $1.1M
Sui
Signed/Unsigned Fee Validation Flaw

What happened

On April 29, 2026, Aftermath Perpetuals on Sui was exploited for approximately $1.14 million USDC. The incident affected the Perps product.

Technical root cause

The builder-fee validation used signed fixed-point semantics for values that were meant to be non-negative, allowing a negative-appearing fee to pass the cap check and inflate collateral during settlement.

How it happened

The attacker supplied a builder fee that passed a signed comparison as negative. During settlement, subtracting that fee turned it into a collateral credit, which the attacker withdrew as USDC.

Protocol details

Classification Protocol Logic
Protocol Type Derivatives
Implementation language Move
Protocol links Website @AftermathFi

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.