Cetus CLMM Hack
What happened
On May 22, 2025, Cetus's Sui concentrated-liquidity market maker was exploited through faulty arithmetic in a shared Move library. The attacker inflated position liquidity with minimal deposits and drained reserves from multiple CLMM pools. Cetus reported approximately $223 million taken before the contracts were paused.
Cetus attributed the flaw to inter_mate's checked_shlw helper. Its overflow guard used a 256-bit limit where this liquidity calculation required a 192-bit bound, allowing an unsafe left-shifted value to pass validation and corrupt liquidity accounting. Cetus specifically said this was unrelated to the previously reported MAX_U64 issue.
Case & protocol details
Attack Timeline
The attacker used a flash swap to temporarily suppress pool prices, then opened a liquidity position in a selected tick range. A faulty overflow check let add_liquidity record an artificially large liquidity amount despite a minimal token contribution. The attacker repeatedly removed liquidity against that false balance to extract pool reserves.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report coindesk.com
- report Cetus Incident Report: May 22, 2025 Attack Disclosure cetusprotocol.notion.site
- report Sui DEX Cetus says overlooked flaw in open-source library used by smart contract led to $223 million exploit theblock.co
- analysis Website reference cointelegraph.com
- analysis Website reference binance.com
- analysis Response to the Cetus Incident - Onchain Community Vote sui.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.