Cetus CLMM Hack

TOTAL LOST $223.0M
Critical Arithmetic Overflow & Underflow Attacks Sui

What happened

On May 22, 2025, Cetus's Sui concentrated-liquidity market maker was exploited through faulty arithmetic in a shared Move library. The attacker inflated position liquidity with minimal deposits and drained reserves from multiple CLMM pools. Cetus reported approximately $223 million taken before the contracts were paused.

Technical Root Cause

Cetus attributed the flaw to inter_mate's checked_shlw helper. Its overflow guard used a 256-bit limit where this liquidity calculation required a 192-bit bound, allowing an unsafe left-shifted value to pass validation and corrupt liquidity accounting. Cetus specifically said this was unrelated to the previously reported MAX_U64 issue.

Case & protocol details

Classification Arithmetic Error / Exchange (DEX)
Protocol Type DEX
Smart Contract Language Move
Official Website www.cetus.zone/
Protocol Twitter/X @cetusprotocol?lang=en

Attack Timeline

The attacker used a flash swap to temporarily suppress pool prices, then opened a liquidity position in a selected tick range. A faulty overflow check let add_liquidity record an artificially large liquidity amount despite a minimal token contribution. The attacker repeatedly removed liquidity against that false balance to extract pool reserves.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.