
The decentralized exchange Cetus Protocol has become the victim of one of the largest heists in the history of the cryptocurrency industry, suffering a loss of $223 million in digital assets. In response, the project has expressed willingness to negotiate with the perpetrators, offering to drop all legal action in exchange for the return of the stolen funds. Simultaneously, the platform’s leadership has announced a $5 million bounty for information leading to the identification and arrest of those responsible.
Cetus Protocol operates as a liquidity protocol built on the Sui and Aptos blockchains. The platform utilizes a concentrated liquidity market-making model, enabling capital providers to allocate assets within specified price ranges. This approach enhances capital efficiency and supports the implementation of advanced trading strategies.
The exchange boasts remarkable performance metrics, with a total trading volume of $57 billion as of May 2025. It serves over fifteen million user accounts and has facilitated 144 million transactions, cementing its status as one of the largest platforms within the cryptocurrency ecosystem.
The incident occurred yesterday. In the immediate aftermath, the protocol’s administrators were compelled to suspend the affected smart contract to initiate a formal investigation. This move allowed technical experts to analyze suspicious activity and mitigate any further damage. Within hours, the project confirmed the theft and reported the successful freezing of $162 million worth of compromised assets.
In a subsequent statement, company representatives disclosed that the attacker had exploited a vulnerable software package, although specific technical details of the breach remain undisclosed—a standard precaution to prevent replication of the attack by other malicious actors. The development team is actively addressing the identified vulnerabilities and fortifying the platform’s security framework.
The protocol’s administrators announced that the root cause of the exploit had been identified, the affected package patched, and the wider ecosystem promptly alerted through community channels to prevent spillover effects on other projects. Such coordination across blockchain initiatives is vital to curbing the spread of similar attacks—timely warnings can safeguard millions of dollars across the industry.
The platform has also succeeded in identifying the perpetrator’s Ethereum wallet address along with associated accounts and is currently working with third-party organizations to trace and freeze the stolen assets. Law enforcement agencies have been notified and have launched their own investigation. International cooperation in cyberspace continues to play an increasingly crucial role in combatting transnational cybercrime.
Cetus Protocol has extended an offer to the attacker: should the stolen funds be returned voluntarily within a limited timeframe, the company pledges not to pursue legal action or involve law enforcement—effectively offering amnesty in exchange for restitution.
Such an approach is sometimes referred to as a “white hat settlement,” wherein a wrongdoer is encouraged to rectify their actions in exchange for immunity from prosecution. The term is borrowed from “white hat hackers”—ethical cybersecurity experts who identify vulnerabilities to help mitigate them. In this instance, the company is essentially inviting the criminal to rebrand themselves as an ally, return the stolen funds, and escape the consequences of incarceration.