Author: f(gautham), co-founder of polynomial; compiled by AIMan@Golden Finance

On May 22, 2025, a hacker stole $223 million from Sui.

Then, an unprecedented event occurred.

Sui validators effectively barred him from entering the Sui blockchain network and froze his funds during his escape.

This completely overturns our understanding of 'decentralized' blockchain.

Here is this bizarre story.

1. Hacker attack

This hacker attack was brutal. This guy drained Cetus' liquidity pool like it was his own home.

$223 million disappeared within hours. SUI memecoins plummeted by 75%. USDC was decoupled to zero on-chain. All swaps failed. Holders couldn't even stop losses. It was a massacre.

VC9SLrki5mIzhlH2zLH6WiT5HNxaA8tI7RHp9DA7.jpeg

aWe3NpcuFi8ntV8FfsVqZNNklPSwMdBYC1eoU1mn.jpeg

But things started to get interesting.

2. Hacker transfers funds

The hacker thought he was unstoppable. He bridged funds to Ethereum and started exchanging them for ETH, transferring over $60 million to Ethereum.

q1BemSgTGDcyygkg6OY0gFGMhq22Mc8YBiGk8IMa.jpeg

A typical escape route. It should have ended there. But...

3. Sui freezes hacker's wallet

Sui validators have other plans.

They directly barred the hacker's wallet from accessing the Sui L1 network. They froze $162 million in transactions. The remaining stolen funds? Locked in a digital prison.

bOoN1xQoMM8GfqhcmUSZGNYdo65aiYs7JhLxgNu2.jpeg

No need for courts to reach a consensus. No lengthy legal procedures. Validators simply said 'no'.

Wait, can they really do that? This is what surprised everyone.

Yes, Sui validators can collectively refuse transactions from specific wallets in extreme cases. This is not automatic and requires broad validator consensus. But it did happen, and it was real-time.

F9m1chVSvMbSaCsNrym6NcblPsftmoPoMia6GbjD.jpeg

4. The cryptocurrency world is divided

Some say, 'If they can freeze funds, is this really decentralized?'

MSij9Y3hZtUzLvNJ5r3USnf2zMYSuTCNOl1fp9Ff.jpegtOCfsvSXz3YNPWWrHfcfBRiETUjGm3ptv3kdoNaR.png

Some say, 'They saved $162 million from being permanently stolen.'

Both sides have valid points.

But importantly: this completely changed the assumptions about Layer-1 security.

5. Details of the hacker attack and Sui team's response

Details are currently unclear, and no official incident report has been received.

Known information: The hacker controlled a liquidity pool valued in SUI and systematically drained it. Cetus initially referred to it as an 'oracle exploit,' but the full exploitation method remains unclear.

ws8L92q9hEZNXLtOH4f9GM3a68KkCSIzz93vmQJx.jpeg

Cetus' response was indeed impressive:

  • Immediately paused contracts to prevent further theft

  • Collaborated with the Sui Foundation and validators

  • Tagged hacker accounts throughout the ecosystem

  • Worked with professional anti-cybercrime organizations

  • Provided white hat settlement terms and professional damage control.

The Sui team stated that most validators agreed to ignore any transactions from the hacker's wallet address and released a PR requesting each validator to deploy patch code so they could take back the $160 million the hacker stole through unsigned transactions.

nXNh4U2xbsMJ33fXsmajR0kSa3Ff0AvsuvlyKxrh.png

6. How to evaluate

Sui's validator coordination speed is incredibly fast. In traditional finance, freezing stolen funds can take weeks. But here? Just a few hours.

Whether you see this as a good emergency response or a centralization issue depends on your perspective.

7. The hacker's mistake

Thought that one person could control the entire chain. His judgment about control was correct, but his judgment about who has control was wrong.

It turns out the problem was not him, but the collective effort of the validators.

Collective power is greater than individual attacks.

8. What's the next step?

Cetus is negotiating with the hacker to return funds.

Relevant legal measures have been initiated.

A complete incident report will be released soon.

But the real question is: will other L1s adopt similar emergency mechanisms?