Scan to Download Gate App
qrCode
More Download Options
Don't remind me again today

How much is a line of code worth? The answer is 1.6 billion dollars — this is not an exaggeration, it is the painful lesson just experienced by Cetus, the largest DEX platform in the Sui ecosystem. A Hacker directly took away 230 million dollars through a breathtakingly ingenious vulnerability.



The key to the matter lies in a seemingly ordinary boundary check: the attacker constructed a special set of inputs that made the value n just satisfy the condition n <= mask, successfully passing the first line of defense. But the real deadly part is the latter half—this n is also greater than or equal to 2^192, and when a left shift of 64 bits is executed, the entire calculation result directly exceeds the storage limit of u256. In an instant of overflow, the function outputs a completely incorrect return value, and the gates of the liquidity pool were thus pried open.

The good news is that the Cetus team has quickly fixed the codebase. But this case serves as a reminder to everyone: security audits of smart contracts leave no room for complacency; even a minor error in bitwise operations can lead to astronomical costs. In the world of DeFi, code is law, and bugs are the loopholes in that law.
CETUS9.24%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 5
  • Repost
  • Share
Comment
0/400
TradFiRefugeevip
· 11-29 04:34
Wow, a bitwise operation can directly yield 230 million, how absurd is that... I used to think Cetus was pretty solid, but now it's been completely exposed.
View OriginalReply0
QuietlyStakingvip
· 11-26 09:13
Wow, a bitwise operation bug directly blew up 230 million, this is why I have always had doubts about the audit of Cetus. I really can't hold it anymore, how can such a low-level error like u256 overflow pass the audit? Code is law, so hackers are judges?
View OriginalReply0
SellTheBouncevip
· 11-26 09:08
It's the same old rhetoric again. Code bugs, audit mistakes, rapid fixes... I've been hearing this for years. The question is, where will the next Cetus be waiting? There's always a lower point, and the same goes for DeFi—there are always bigger vulnerabilities.
View OriginalReply0
ContractHuntervip
· 11-26 09:04
Damn, the u256 overflow directly broke through 230 million, that's why I never touch pools that haven't been audited.
View OriginalReply0
CountdownToBrokevip
· 11-26 08:58
Damn, a bitwise operation bug just cost 230 million, that's just too harsh.
View OriginalReply0
  • Pin
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)