Sui’s 90.9% Vote Authorized Two Recovery Transactions Without Hacker Signatures
On May 22, 2025, a single integer-overflow bug drained an estimated $223 million from Cetus, the biggest DEX on Sui. Validators froze about $162 million by ignoring the attacker’s transactions, and a stake-weighted onchain vote closed early on May 29 at 90.9% in favor — authorizing a protocol upgrade that moves the frozen funds through exactly two prespecified transactions, without the hackers’ signatures, into a 4-of-6 multisig trust.

3-Minute Fast Briefing
- The ParadoxOn May 22, 2025, an attacker exploited a flawed integer-overflow check in a shared Move math library to drain an estimated $223 million from Cetus, Sui’s biggest decentralized exchange, while more than $60 million reportedly bridged to Ethereum.
- The Turning PointSui’s onchain, stake-weighted validator vote opened on May 27 and concluded early on May 29 with validators representing 90.9% of stake voting yes, authorizing a protocol upgrade to move the roughly $162 million in frozen funds into a 4-of-6 multisig trust without the hackers’ signatures.
- The LegacyMysten Labs merged the address-aliasing upgrade on May 30, scoped to exactly two prespecified recovery transactions, reopening the industry-wide debate over whether validator coordination is a rescue feature or a centralization warning.
Chronological Timeline
Cetus, the biggest DEX on Sui, is exploited through a flawed overflow check; security analyses estimate about $223 million taken.
Validators identify the two attacker addresses and ignore their transactions; Cetus says most of the stolen funds are contained while more than $60 million reportedly reaches Ethereum.
A reported onchain offer lets the attacker keep about $6 million for returning funds; silence follows, and Cetus announces a $5 million identification bounty.
Stake-weighted validator voting opens May 27 and concludes early on May 29 at 90.9% in favor, with 1.5% abstaining and 7.2% not participating.
MystenLabs/sui PR #22237 merges, enabling exactly two recovery transactions through restricted address aliasing without hacker signatures.
1. One Wrong Constant Broke Sui’s Largest DEX
On May 22, 2025, an attacker drained Cetus, the largest decentralized exchange on the Sui network, through what security firm Halborn later traced to a flawed overflow check. Cetus reported that more than $220 million was stolen; Halborn estimated losses at $223 million. Within hours, the central question was no longer how the money left, but how much could still be contained.[3][6]
The exploit mechanics were strikingly concise. The attack opened with a flash loan — reported by rekt at 56,700 SUI — followed by taking a liquidity position across a narrow tick range of [300000, 300200], funded by a single SCA token.[3][4]
The vulnerability resided in checked_shlw, a helper function intended to verify whether shifting a 256-bit integer left by 64 bits would overflow. Halborn found that the code checked against 0xFFFFFFFFFFFFFFFF << 192 rather than 0x1 << 192. Values that should have failed passed the check, the arithmetic overflowed, and one deposited token was credited as an astronomical liquidity stake.[3]
The attacker withdrew that phantom position across multiple pools. rekt reported the minted liquidity reached roughly 10³⁴ units and noted that every Cetus AMM pool was hit. Move protects against most arithmetic overflows, but permits bit shifts to overflow by design. The flaw sat in the shared integer-mate library, which Zellic stated was outside the scope of its April 2025 audit — and Verichains reportedly found the same function copied across other Sui protocols.[4]
2. The Freeze That Started the Argument
The emergency response began immediately on May 22, well before any governance ballot. Sui validators coordinated to ignore transactions from the attacker's addresses, and Cetus reported that about $162 million of the stolen funds was successfully frozen mid-flight. That validator action contained the majority of the exploit.[6][1]
“A large number of validators identified the addresses with the stolen funds and are ignoring transactions on those addresses until further notice.”[6]— Sui Foundation, May 22, 2025 statement
Not all assets were caught on Sui. Independent tracking revealed that more than $60 million crossed the Wormhole bridge to Ethereum, where roughly 20,000 ETH was transferred to a fresh wallet. Security firm Hacken’s Extractor tool estimated the bridged total at about $63 million.[4][6]
Negotiation followed quickly. As reported by rekt, Cetus and blockchain intelligence firm Inca Digital signed an onchain message offering the attacker about $6 million (2,324 ETH) to return the funds. When silence followed, Cetus posted a $5 million bounty for information leading to identification and arrest. Meanwhile, the freeze ignited controversy: if validators could halt fund transfers without a vote, critics asked what ownership truly meant on Sui.[4][8]
3. A Protocol Upgrade on the Ballot
Five days after the exploit, at 1pm PST on May 27, 2025, Sui launched an onchain community vote. Validators cast stake-weighted votes — yes, no, or abstain — through a transparent smart contract. Votes were final once submitted, and the Sui Foundation's own stake was excluded to ensure procedural neutrality.[1][5]
The approval threshold was strict: more than 50% of total network stake (excluding abstentions) had to participate, and yes-weighted stake had to exceed no-weighted stake. The schedule allowed up to seven days with early closure permitted after two once mathematically decisive. Token holders participated indirectly through their delegated validators.[1]
The vote concluded early on May 29, 2025. Validators representing 90.9% of stake voted yes, while 1.5% abstained and 7.2% did not participate, per governance records reported by Cointelegraph. The vote authorized moving the frozen funds into a multisig trust — not a blanket seizure power, but authorization for two specific recovery transactions.[7][1]
“Validators representing 90.9% of stake have said “yes” in the onchain community vote, and the vote has concluded early.”[1]— Sui Foundation, vote-conclusion update
4. Two Transactions Without Hacker Signatures: Address Aliasing
Software updates moved in lockstep with the ballot. On May 27, developer mystenmark opened pull request #22237 — titled “Protocol update to allow recovery of stolen funds” — on the MystenLabs/sui repository. It merged on May 30 across nine commits on branch recover-via-address-alias.[2]
“ProtocolConfig can specify address aliases which allow a signature from address A to act as the sender address B.”[2]— mystenmark, PR #22237 description
The upgrade established two tuples containing hacker address, aliased address, and exact TransactionDigest — authorizing exactly one recovery transaction per hacker address. The address deny list would be bypassed strictly for those two allowed transactions; the proposal and PR said the crafted transactions would be publicized for community inspection before the protocol upgrade.[1][2]
“This mechanism is specific to the two recovery transactions and cannot be used for any other purpose”[1]— Sui Foundation, protocol upgrade technical details
Custody of the funds to be recovered was assigned to a 4-of-6 multisig trust wallet: two keys held by Cetus, two by the Sui Foundation, and two by OtterSec, an auditor characterized by the Foundation as trusted in the Sui ecosystem. Cetus was to propose and sign recovery transactions, OtterSec to verify they conformed to the public plan, and the Foundation to sign only if other signers were unable.[1]
5. Held in Trust: The Receipt for the Rescue
After the vote, the Sui Foundation said the frozen assets would be moved to the multisig trust pending distribution under Cetus’s recovery plan, which included Cetus treasury funds and a loan from the Foundation. Cetus stated that it targeted full recovery and a restart in approximately one week and that a dedicated compensation contract was under development and would undergo auditor review before deployment.[1][7]
The intervention sparked intense debate across the cryptocurrency sector. As Cointelegraph's Finance Redefined reported, decentralization advocates criticized the validators' ability to pause asset transfers as evidence of centralization. Conversely, other industry observers commended the rapid coordination as essential protection when ecosystem users are exploited.[8]
The record presents a striking contrast. On one side stood an emergency validator freeze before any vote, followed by a narrow, stake-ratified protocol upgrade limited to two transactions and a split multisig. On the other stood proof that a stake supermajority can redirect funds without the holder's signature.[1][2][8]
That tension defines the legacy of the Cetus recovery decision. Cetus requested it, validators representing 90.9% of stake approved it, code narrowly constrained it, and OtterSec was assigned to verify proposed distributions against the public plan — yet the network still had to treat two addresses as exceptions. As the Foundation emphasized, protocol governance requires active participation; on Sui, that participation authorized how about $162 million in frozen funds would be recovered.[1]
Key Takeaways for Investors & Builders
Audit the math library everyone shares
The Cetus bug lived in checked_shlw, a function in the shared integer-mate library, and the newest audit reportedly never covered that file. Shared dependencies concentrate risk: overflow checks, rounding helpers, and low-level arithmetic deserve the same scrutiny as headline contract logic, in every protocol that copies them.
Emergency response is part of the investment case
The freeze and the vote materially changed the loss outcome: about $162 million of an estimated $223 million was contained and placed on a path back to users. Investors pricing a chain should price its intervention capability too — validator concentration, upgrade speed, and who can act when things break.
Governance can move coins without their owner’s signature
Sui’s recovery was requested by Cetus, scoped by code, ratified by validators representing 90.9% of stake, and assigned to a three-party multisig trust. It still proves the underlying point: a supermajority mechanism can authorize moving funds their holder did not sign away. Whether that is a safety net or a precedent is the question every decentralized network must answer in advance.
Connected Stories in this Universe
Explore the chain reaction of historical breakthroughs, blunders, and legends.

The 100,000-Byte Blank Check: Bitcoin Core v30, OP_RETURN, and the Knots Rebellion
Core's 100,000-byte OP_RETURN default met Knots' 42-byte filter: a relay-policy war over spam and node choice that never touched consensus.
Read story →
One Signature Can Rewrite Your Wallet: Ethereum's EIP-7702 Paradox
Ethereum's Pectra upgrade let plain key wallets run code through EIP-7702 delegation. The persistence that enables batching and recovery also became phishing's newest target.
Read story →
Fighting Sandwich Attacks With an Auction: CoW Protocol’s MEV Reversal
How Gnosis turned signed trade intents, solver competition and a cow-shaped pun into an MEV-resistant auction.
Read story →Sources & References
- [1]Source 1: Response to the Cetus Incident – Onchain Community VoteSui Foundation · 2025-05-27Accessed 2026-08-23
- [2]Source 2: Protocol update to allow recovery of stolen funds (PR #22237)MystenLabs/sui (GitHub) · 2025-05-27Accessed 2026-08-23
- [3]Source 3: Explained: The Cetus Hack (May 2025)Halborn · 2025-05-27Accessed 2026-08-23
- [4]Source 4: Cetus – RektRekt News · 2025-05-23Accessed 2026-08-23
- [5]Source 5: sui-foundation/recovery-vote: Cetus recovery voting contractSui Foundation (GitHub)Accessed 2026-08-23
- [6]Source 6: Sui validators freeze majority of stolen funds in $220M Cetus hackCointelegraph · 2025-05-22Accessed 2026-08-23
- [7]Source 7: Sui passes vote on Cetus’ $162M frozen from exploitCointelegraph · 2025-05-30Accessed 2026-08-23
- [8]Source 8: Sui vote on $162M Cetus funds ignites decentralization debate in DeFiCointelegraph (Finance Redefined) · 2025-05-30Accessed 2026-08-23