Market Cap: $2.8791T 0.21%
Volume(24h): $96.2687B -4.02%
  • Market Cap: $2.8791T 0.21%
  • Volume(24h): $96.2687B -4.02%
  • Fear & Greed Index:
  • Market Cap: $2.8791T 0.21%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$83993.093959 USD

0.22%

ethereum
ethereum

$2689.793184 USD

0.78%

tether
tether

$0.999787 USD

0.00%

bnb
bnb

$773.105571 USD

0.11%

xrp
xrp

$1.552232 USD

1.56%

usd-coin
usd-coin

$0.999896 USD

0.00%

solana
solana

$120.433167 USD

3.80%

tron
tron

$0.337303 USD

-0.36%

zcash
zcash

$1536.901627 USD

-0.27%

hyperliquid
hyperliquid

$91.904809 USD

-0.20%

dogecoin
dogecoin

$0.097737 USD

3.08%

chainlink
chainlink

$14.080883 USD

5.21%

monero
monero

$554.283914 USD

-3.05%

cardano
cardano

$0.255122 USD

3.19%

unus-sed-leo
unus-sed-leo

$8.909967 USD

1.35%

Cryptocurrency News Articles

Tiny Overflow Bug in Cetus Smart Contract Was Root Cause of $230M DeFi Loss

May 26, 2025 at 04:07 pm

SlowMist confirmed bug in checked_shlw function was root cause of $230M DeFi loss. Tiny overflow bug in Cetus smart contract allowed attacker to fake massive liquidity deposits.

Tiny Overflow Bug in Cetus Smart Contract Was Root Cause of $230M DeFi Loss

On May 22, something alarming happened in the SUI blockchain world. Prices on the Cetus decentralized exchange (DEX) suddenly dropped, and its liquidity pools were drained. The total estimated loss was over $230 million.

Several reports quickly implicated a single triple-entry arbitrageur who used a flash loan to crash a token price instantly and siphon off funds from multiple protocols. However, the precise technical vulnerability that enabled this massive exploit remained a subject of discussion.

Now, renowned blockchain security team SlowMist has released a detailed analysis, revealing a tiny overflow bug in Cetus’ smart contract as the root cause of the staggering DeFi loss.

The checked_shlw function, designed to check for errors like overflows, failed to properly detect an overflow in the get_delta_a function, which is used to calculate the delta of token A when adding liquidity.

This bug allowed the attacker to claim to be adding a huge amount of liquidity by displaying a nearly impossible price and submitting only 1 token, while the system expected 367506680905089974005506088888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888

Original source:coinpedia

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Sep 26, 2026