Sui is a permissionless Layer 1 blockchain, designed from the ground up to enable creators and developers to build experiences that cater to the next billion users in Web3. It is horizontally scalable, enabling a wide range of application development with unrivaled speed and low cost.
according to Blockaid monitoring, an ongoing attack has occurred on Aftermath Finance's perpetual contract protocol on the Sui Network, with approximately $1.1 million worth of USDC stolen across 11 transactions within about 36 minutes. Analysis indicates the vulnerability stems from a fee accounting flaw in the perpetual contract liquidation system, which the attacker exploited to artificially inflate synthetic collateral and drain funds from the protocol's treasury.
According to on-chain security firm Blockaid (@blockaid_), AftermathFi’s perpetual contract on Sui Network was exploited via a vulnerability on April 29. The attacker (address: 0x1a65...2d41e) stole approximately $1.1 million in USDC across 11 transactions within roughly 36 minutes. The attack exploited a flaw in the perpetual contract liquidation fee calculation, enabling illicit withdrawals from the protocol’s treasury via synthetic collateral inflation.
Scallop, a lending protocol in the Sui ecosystem, announced on X that a vulnerability was discovered in a subsidiary contract related to Scallop’s sSUI reward pool, resulting in the loss of approximately 150,000 SUI. The affected contract has been frozen. Scallop stated that its core contracts remain secure and only the sSUI reward pool is impacted; all other reward pools are unaffected and secure. Scallop will fully cover 100% of the losses and will release further updates as soon as possible.
According to an official announcement by Volo, a security vulnerability occurred today on the Sui network involving Volo—a BTCFi and LST protocol—resulting in the theft of approximately $3.5 million in assets (including WBTC, XAUm, and USDC) from three specific vaults. Immediately after the incident, the team notified the Sui Foundation and ecosystem partners and froze all vaults to prevent further losses. Volo stated that the vulnerability affected only these three vaults; the remaining vaults are not exposed to the same attack vector, and the other ~$28 million in TVL remains secure. The official announcement emphasized that Volo will bear the loss entirely and will not pass it on to users. A comprehensive post-mortem report and remediation plan will be released upon completion of the investigation.
Scallop, a lending protocol in the Sui ecosystem, announced on X that a vulnerability was discovered in a subsidiary contract related to Scallop’s sSUI reward pool, resulting in the loss of approximately 150,000 SUI. The affected contract has been frozen. Scallop stated that its core contracts remain secure and only the sSUI reward pool is impacted; all other reward pools are unaffected and secure. Scallop will fully cover 100% of the losses and will release further updates as soon as possible.
According to an official announcement by Volo, a security vulnerability occurred today on the Sui network involving Volo—a BTCFi and LST protocol—resulting in the theft of approximately $3.5 million in assets (including WBTC, XAUm, and USDC) from three specific vaults. Immediately after the incident, the team notified the Sui Foundation and ecosystem partners and froze all vaults to prevent further losses. Volo stated that the vulnerability affected only these three vaults; the remaining vaults are not exposed to the same attack vector, and the other ~$28 million in TVL remains secure. The official announcement emphasized that Volo will bear the loss entirely and will not pass it on to users. A comprehensive post-mortem report and remediation plan will be released upon completion of the investigation.
Odaily News: Hong Kong-based crypto payment company RedotPay announced the addition of support for SUI and USDC-Sui within its application. Users can now spend and transfer funds in over 100 countries globally using its card and payment services. This integration, built on the Sui network developed by Mysten Labs, enables support for native USDC, marking an expansion from cross-chain assets to native assets.RedotPay stated that it currently has over 7 million users, with an annualized payment volume exceeding $10 billion. (TechinAsia)
According to a post on Grayscale’s official website, the firm has updated its list of cryptocurrencies under consideration for future investment products. Per the latest list, the “Currencies” category includes Bitcoin and XRP; the “Smart Contract Platforms” category now adds Stacks, Sui, Toncoin, and Tron; the “Financials” category includes assets under consideration such as Ethena, Hyperliquid, and Jupiter; the “Consumer & Culture” category features Dogecoin and Decentraland; the “AI” category includes Worldcoin, Virtuals Protocol, Story, and Grass; and the “Utilities & Services” category comprises Chainlink, LayerZero, and Helium. Grayscale stated that this list is reviewed quarterly to provide investors with diversified digital asset investment options.
according to Blockaid monitoring, an ongoing attack has occurred on Aftermath Finance's perpetual contract protocol on the Sui Network, with approximately $1.1 million worth of USDC stolen across 11 transactions within about 36 minutes. Analysis indicates the vulnerability stems from a fee accounting flaw in the perpetual contract liquidation system, which the attacker exploited to artificially inflate synthetic collateral and drain funds from the protocol's treasury.
According to on-chain security firm Blockaid (@blockaid_), AftermathFi’s perpetual contract on Sui Network was exploited via a vulnerability on April 29. The attacker (address: 0x1a65...2d41e) stole approximately $1.1 million in USDC across 11 transactions within roughly 36 minutes. The attack exploited a flaw in the perpetual contract liquidation fee calculation, enabling illicit withdrawals from the protocol’s treasury via synthetic collateral inflation.
Scallop, a lending protocol in the Sui ecosystem, announced on X that a vulnerability was discovered in a subsidiary contract related to Scallop’s sSUI reward pool, resulting in the loss of approximately 150,000 SUI. The affected contract has been frozen. Scallop stated that its core contracts remain secure and only the sSUI reward pool is impacted; all other reward pools are unaffected and secure. Scallop will fully cover 100% of the losses and will release further updates as soon as possible.
According to an official announcement by Volo, a security vulnerability occurred today on the Sui network involving Volo—a BTCFi and LST protocol—resulting in the theft of approximately $3.5 million in assets (including WBTC, XAUm, and USDC) from three specific vaults. Immediately after the incident, the team notified the Sui Foundation and ecosystem partners and froze all vaults to prevent further losses. Volo stated that the vulnerability affected only these three vaults; the remaining vaults are not exposed to the same attack vector, and the other ~$28 million in TVL remains secure. The official announcement emphasized that Volo will bear the loss entirely and will not pass it on to users. A comprehensive post-mortem report and remediation plan will be released upon completion of the investigation.
Odaily News: Hong Kong-based crypto payment company RedotPay announced the addition of support for SUI and USDC-Sui within its application. Users can now spend and transfer funds in over 100 countries globally using its card and payment services. This integration, built on the Sui network developed by Mysten Labs, enables support for native USDC, marking an expansion from cross-chain assets to native assets.RedotPay stated that it currently has over 7 million users, with an annualized payment volume exceeding $10 billion. (TechinAsia)
According to a post on Grayscale’s official website, the firm has updated its list of cryptocurrencies under consideration for future investment products. Per the latest list, the “Currencies” category includes Bitcoin and XRP; the “Smart Contract Platforms” category now adds Stacks, Sui, Toncoin, and Tron; the “Financials” category includes assets under consideration such as Ethena, Hyperliquid, and Jupiter; the “Consumer & Culture” category features Dogecoin and Decentraland; the “AI” category includes Worldcoin, Virtuals Protocol, Story, and Grass; and the “Utilities & Services” category comprises Chainlink, LayerZero, and Helium. Grayscale stated that this list is reviewed quarterly to provide investors with diversified digital asset investment options.