BlueMove DEX Hack

Reported loss $529K
Sui
Reserve Desynchronization

What happened

On July 11, 2026, an attacker drained BlueMove DEX liquidity pools on Sui. Independent on-chain analysis reports about 714,000 SUI, roughly $528,000 at the time, moved out; BlueMove suspended the protocol and announced compensation, so the eventual net loss should not be read as settled from this exposure figure.

Technical root cause

Available analysis describes a cross-version reserve-desynchronization and accounting flaw in the legacy Move AMM; BlueMove's public notice confirms the incident but does not publish a definitive root-cause report.

How it happened

The attacker exploited a legacy BlueMove AMM reserve and accounting path, drained multiple pools, and bridged proceeds as USDC through Wormhole. BlueMove later suspended operations and published a compensation process for affected users.

Protocol details

Classification Token & Share Accounting
Protocol Type DEX
Implementation language Move
Protocol links Website @BlueMove_OA

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.