Author: f(gautham), co-founder of polynomial; compiled by AIMan@Golden Financial
On May 22, 2025, a hacker stole 223 million dollars from Sui.
Then, an unprecedented event happened.
Sui validators actually prohibited him from entering the Sui blockchain network and froze his funds while he was fleeing.
This completely overturns our understanding of 'decentralized' blockchains.
Here is this bizarre story.
1. Hacker Attack
This hacker attack was very brutal. This guy drained Cetus's liquidity pool as if it were his own house.
223 million dollars disappeared within a few hours. SUI memecoins plummeted by 75%. USDC decoupled to zero on-chain. All swaps failed. Holders couldn't even stop losses. It was a massacre.


But things started to get interesting.
2. Hacker transfers funds
The hacker thought he was unstoppable. He bridged the funds to Ethereum and began exchanging them for ETH, having transferred over 60 million dollars to Ethereum.

A typical escape route. It should have ended here. But...
3. Sui freezes the hacker's wallet
Sui validators have other plans.
They directly prohibited the hacker's wallet from entering the Sui L1 network. They froze 162 million dollars in transactions. The remaining stolen funds? Locked in a digital prison.

No need for courts to reach a consensus. No lengthy legal procedures. Validators just had to say 'no.'
Wait, can they really do that? That's what surprises everyone.
That's right, Sui validators can collectively reject transactions from specific wallets in extreme cases. This is not automatic and requires broad validator consensus. But it did happen, and it was real-time.

4. The cryptocurrency world is divided
Some say, 'If they can freeze funds, is this really decentralized?'


Some say, 'They saved 162 million dollars from being permanently stolen.'
Both sides have valid points.
But importantly: this completely changed the assumptions about Layer-1 security.
5. Details of the hacker attack and Sui team's response
The specific details are still unclear, and no official incident report has been received.
Known information: The hacker controlled the liquidity pool priced in SUI and systematically drained it. Cetus initially referred to it as an 'oracle vulnerability,' but the complete method of exploitation is still unclear.

Cetus's response is indeed impressive:
Immediately suspend contracts to prevent further theft
Collaborate with the Sui Foundation and validators
Tag the hacker accounts throughout the ecosystem
Collaborate with professional anti-cybercrime organizations
Provide white-hat settlement terms for professional damage control.
The Sui team stated that most validators agreed to ignore any transactions from the hacker's wallet address and released a PR requesting each validator to deploy patch code so they could reclaim the 162 million dollars stolen by the hacker through unsigned transactions.

6. How to evaluate
Sui's validators coordinated extremely quickly. In traditional finance, freezing stolen funds takes weeks. But here? Just a few hours.
Whether you think this is a good emergency response or a centralization issue depends on your perspective.
7. The Hacker's Mistake
He thought one person could control the entire chain. His judgment on control was correct, but his judgment on who holds the control was wrong.
It turns out the problem wasn't with him, but with the collective effort of the validators.
Collective power is greater than individual attacks.
8. What's next?
Cetus is negotiating with the hacker regarding the return of the funds.
Relevant legal measures have been initiated.
A complete incident report is forthcoming.
But the real question is: will other L1s adopt similar emergency mechanisms?
