
加密韋馱|Crypto V🇹🇭|May 30, 2025 07:11
The announcement released by Cetus this morning regarding the resumption of online operations and the recovery and compensation plan for stolen funds
The proposal to freeze and recover Cetus' stolen funds by Sui has been approved by 90% of the validation node votes.
Cetus will also complete a comprehensive recovery and restart within approximately one week, including data recovery, restarting the upgraded CLMM contract, and fully restoring all suspended product features (including LP functionality, etc.)
The recovery will be completed according to the following steps:
1. Protocol upgrade: Sui validators will implement an upgrade by transferring frozen funds to Cetus' multi signature trust account (with Cetus, OtterSec, and Sui Foundation as key holders).
2. CLMM contract upgrade: The upgrade to support emergency pool recovery has been completed and is currently undergoing audit.
3. Data recovery: We will recover pool data and calculate the liquidity loss for each attacked pool.
4. Asset Conversion and Deposit: Due to the attacker's extensive exchange during the event, the recovered assets have significantly changed from their original form. We will be guided by Cetus' principle of goodwill and adopt a strategy of minimizing large redemptions or excessive slippage as much as possible to ensure efficient and fair rebalancing of the pool.
5. Compensation contract: A specialized compensation contract is currently under development and will be audited before deployment.
6. Peripheral product upgrade: We are upgrading relevant modules to ensure full compatibility with the upgraded CLMM contract and achieve smooth restart.
7. Comprehensive restart of the protocol: All core product functions will resume operation. Affected LP users will regain their restored liquidity, and any remaining losses can be claimed through compensation contracts. The unaffected pools will continue to operate normally.
8. Cetus fully resumes online launch
Fun fact:
Cetus was the first project to implement Uni V3 DEX in the Move language (including Sui and Aptos), and its codebase is also the most widely referenced in the Move language, accompanying almost all algorithm and specification upgrades throughout the history of the Move language
So, in the event of an attack, it is necessary for all parties within the Sui ecosystem to communicate and respond quickly, while suspending contracts. Because each project may have used Cetus' code to varying degrees, have the attacked code also been used by themselves, and are there any other vulnerabilities that have not yet been exploited
Security is something that everyone can say how impressive they are before anything goes wrong, but in reality, what determines user trust is the pattern and ability to deal with problems after they occur
Wormhole was stolen 200 million yuan back then and is still Sui's largest bridge, while Bybit's large customer base has increased even more since the theft of 1.5 billion yuan. Why?
Because the two companies had problems, it demonstrated their decisive handling ability and determination to provide a safety net
This is not something that can be solved with just speaking up
Share To
HotFlash
APP
X
Telegram
CopyLink