Typus Finance—a perpetuals and options decentralized exchange on the Sui Network—suffered a major exploit on October 15, losing over $3 million in tokens. This is the third major exploit on the Sui SUI $2.62 24h volatility: 3.4% Market cap: $9.48 B Vol. 24h: $1.40 B DeFi ecosystem in 2025, preceded by the Cetus Protocol hack in May and the Nemo Protocol exploit in September. A postmortem published on October 16 details the exploit, the event timeline, and the root cause, which involves an unaudited TLP contract and an oracle vulnerability regarding a lack of authority checks. Overall, the attacker drained $3.44 million worth of SUI, USDC, xBTC, and suiETH, according to the document. Precisely, Typus lost 588,357.9 SUI, 1,604,034.7 USDC, 0.6 xBTC, and 32.227 suiETH. “Two process causes compounded this issue. First, the vulnerable oracle module, originally deployed on November 13, 2024, was not included in the scope of our May 2025 audit conducted by MoveBit. Second, the alert frequency for our on-chain monitoring service was not configured for immediate detection of this specific event type.” While a significant exploit, only the TLP contract was affected. Funds deposited in the SAFU and DeFi Options Vaults remain secure. The team asserts that they have received active support from the Sui Foundation, Mysten Labs, MoveBit, SlowMist, and Hypernative—now working on an “asset recovery plan.” We are now publishing our full post-mortem report on the October 15 TLP exploit. The report details the incident timeline, root cause analysis, an impact assessment of approx. $3.44M USD, and our response plan. We confirm that funds in our SAFU and DeFi Options Vaults were… — Typus Finance (@TypusFinance) October 16, 2025 Third Major Exploit on Sui in 2025 Before Typus Finance, two other DeFi protocols building on the Sui blockchain suffered major exploits this year. First, CETUS Protocol—the primary decentralized exchange on Sui—suffered a major hack in May 2025, losing more than $220 million in assets, as Coinspeaker reported. In its postmortem, Cetus admitted that it was relaxed in its approach regarding vigilance, according to Cointelegraph. What followed was a highly controversial governance vote that allowed the Sui Foundation, Cetus, and OtterSec to seize the stolen funds from the attacker’s Sui account that they had previously decided to freeze. This seizure effectively broke Sui’s cryptographic security by creating a special private key with universal signing capacity. “If this vote passes, the next Sui release will include a protocol upgrade that enables a one-time authentication of two special transactions. These transactions will be hard-coded with the two attacker addresses, stolen asset objects, and their destination. It will verify the voting results and, if approved, transfer the stolen funds from the attacker addresses to a Cetus multi-sig wallet with Cetus, the Sui Foundation, and OtterSec acting as signers.” Governance Vote | Source: Sui Explorer Most recently, in September, Sui-based yield protocol Nemo was exploited for $2.4 million in USDC, according to a report from CoinDesk. Commentators on X now criticize Typus for what some are calling “negligence” for both the lack of a proper audit and the use of an oracle without a proven track record, instead of using more consolidated products like Chainlink LINK $17.75 24h volatility: 2.1% Market cap: $12.37 B Vol. 24h: $908.65 M . Users have a clear potential cause of action against Typus for gross negligence and misrepresentation. The decision to rely on an unproven oracle system like Pyth, despite the well-documented reliability of Chainlink, demonstrates a failure to exercise reasonable care in… — Team Cucumber (@TeamCucumber777) October 15, 2025 These events have fueled uncertainty in a market that is still struggling to recover from the unprecedented $19 billion liquidations from October 10’s crash. As Coinspeaker reported earlier today, another $540 million in liquidations amid sell-out expectations regarding Mt. Gox repayments. nextThe post Typus Finance’s Unaudited Contract Loses $3M, 3rd Major Sui Exploit in 2025 appeared first on Coinspeaker.Typus Finance—a perpetuals and options decentralized exchange on the Sui Network—suffered a major exploit on October 15, losing over $3 million in tokens. This is the third major exploit on the Sui SUI $2.62 24h volatility: 3.4% Market cap: $9.48 B Vol. 24h: $1.40 B DeFi ecosystem in 2025, preceded by the Cetus Protocol hack in May and the Nemo Protocol exploit in September. A postmortem published on October 16 details the exploit, the event timeline, and the root cause, which involves an unaudited TLP contract and an oracle vulnerability regarding a lack of authority checks. Overall, the attacker drained $3.44 million worth of SUI, USDC, xBTC, and suiETH, according to the document. Precisely, Typus lost 588,357.9 SUI, 1,604,034.7 USDC, 0.6 xBTC, and 32.227 suiETH. “Two process causes compounded this issue. First, the vulnerable oracle module, originally deployed on November 13, 2024, was not included in the scope of our May 2025 audit conducted by MoveBit. Second, the alert frequency for our on-chain monitoring service was not configured for immediate detection of this specific event type.” While a significant exploit, only the TLP contract was affected. Funds deposited in the SAFU and DeFi Options Vaults remain secure. The team asserts that they have received active support from the Sui Foundation, Mysten Labs, MoveBit, SlowMist, and Hypernative—now working on an “asset recovery plan.” We are now publishing our full post-mortem report on the October 15 TLP exploit. The report details the incident timeline, root cause analysis, an impact assessment of approx. $3.44M USD, and our response plan. We confirm that funds in our SAFU and DeFi Options Vaults were… — Typus Finance (@TypusFinance) October 16, 2025 Third Major Exploit on Sui in 2025 Before Typus Finance, two other DeFi protocols building on the Sui blockchain suffered major exploits this year. First, CETUS Protocol—the primary decentralized exchange on Sui—suffered a major hack in May 2025, losing more than $220 million in assets, as Coinspeaker reported. In its postmortem, Cetus admitted that it was relaxed in its approach regarding vigilance, according to Cointelegraph. What followed was a highly controversial governance vote that allowed the Sui Foundation, Cetus, and OtterSec to seize the stolen funds from the attacker’s Sui account that they had previously decided to freeze. This seizure effectively broke Sui’s cryptographic security by creating a special private key with universal signing capacity. “If this vote passes, the next Sui release will include a protocol upgrade that enables a one-time authentication of two special transactions. These transactions will be hard-coded with the two attacker addresses, stolen asset objects, and their destination. It will verify the voting results and, if approved, transfer the stolen funds from the attacker addresses to a Cetus multi-sig wallet with Cetus, the Sui Foundation, and OtterSec acting as signers.” Governance Vote | Source: Sui Explorer Most recently, in September, Sui-based yield protocol Nemo was exploited for $2.4 million in USDC, according to a report from CoinDesk. Commentators on X now criticize Typus for what some are calling “negligence” for both the lack of a proper audit and the use of an oracle without a proven track record, instead of using more consolidated products like Chainlink LINK $17.75 24h volatility: 2.1% Market cap: $12.37 B Vol. 24h: $908.65 M . Users have a clear potential cause of action against Typus for gross negligence and misrepresentation. The decision to rely on an unproven oracle system like Pyth, despite the well-documented reliability of Chainlink, demonstrates a failure to exercise reasonable care in… — Team Cucumber (@TeamCucumber777) October 15, 2025 These events have fueled uncertainty in a market that is still struggling to recover from the unprecedented $19 billion liquidations from October 10’s crash. As Coinspeaker reported earlier today, another $540 million in liquidations amid sell-out expectations regarding Mt. Gox repayments. nextThe post Typus Finance’s Unaudited Contract Loses $3M, 3rd Major Sui Exploit in 2025 appeared first on Coinspeaker.

Typus Finance’s Unaudited Contract Loses $3M, 3rd Major Sui Exploit in 2025

Typus Finance—a perpetuals and options decentralized exchange on the Sui Network—suffered a major exploit on October 15, losing over $3 million in tokens. This is the third major exploit on the Sui SUI $2.62 24h volatility: 3.4% Market cap: $9.48 B Vol. 24h: $1.40 B DeFi ecosystem in 2025, preceded by the Cetus Protocol hack in May and the Nemo Protocol exploit in September.

A postmortem published on October 16 details the exploit, the event timeline, and the root cause, which involves an unaudited TLP contract and an oracle vulnerability regarding a lack of authority checks. Overall, the attacker drained $3.44 million worth of SUI, USDC, xBTC, and suiETH, according to the document. Precisely, Typus lost 588,357.9 SUI, 1,604,034.7 USDC, 0.6 xBTC, and 32.227 suiETH.

While a significant exploit, only the TLP contract was affected. Funds deposited in the SAFU and DeFi Options Vaults remain secure. The team asserts that they have received active support from the Sui Foundation, Mysten Labs, MoveBit, SlowMist, and Hypernative—now working on an “asset recovery plan.”

Third Major Exploit on Sui in 2025

Before Typus Finance, two other DeFi protocols building on the Sui blockchain suffered major exploits this year.

First, CETUS Protocol—the primary decentralized exchange on Sui—suffered a major hack in May 2025, losing more than $220 million in assets, as Coinspeaker reported. In its postmortem, Cetus admitted that it was relaxed in its approach regarding vigilance, according to Cointelegraph.

What followed was a highly controversial governance vote that allowed the Sui Foundation, Cetus, and OtterSec to seize the stolen funds from the attacker’s Sui account that they had previously decided to freeze. This seizure effectively broke Sui’s cryptographic security by creating a special private key with universal signing capacity.

Governance Vote | Source: Sui Explorer

Governance Vote | Source: Sui Explorer

Most recently, in September, Sui-based yield protocol Nemo was exploited for $2.4 million in USDC, according to a report from CoinDesk.

Commentators on X now criticize Typus for what some are calling “negligence” for both the lack of a proper audit and the use of an oracle without a proven track record, instead of using more consolidated products like Chainlink LINK $17.75 24h volatility: 2.1% Market cap: $12.37 B Vol. 24h: $908.65 M .

These events have fueled uncertainty in a market that is still struggling to recover from the unprecedented $19 billion liquidations from October 10’s crash. As Coinspeaker reported earlier today, another $540 million in liquidations amid sell-out expectations regarding Mt. Gox repayments.

next

The post Typus Finance’s Unaudited Contract Loses $3M, 3rd Major Sui Exploit in 2025 appeared first on Coinspeaker.

Market Opportunity
Major Logo
Major Price(MAJOR)
$0.11494
$0.11494$0.11494
-1.17%
USD
Major (MAJOR) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus

BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus

The post BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus appeared on BitcoinEthereumNews.com. Press Releases are sponsored content and not a part of Finbold’s editorial content. For a full disclaimer, please . Crypto assets/products can be highly risky. Never invest unless you’re prepared to lose all the money you invest. Curacao, Curacao, September 17th, 2025, Chainwire BetFury steps onto the stage of SBC Summit Lisbon 2025 — one of the key gatherings in the iGaming calendar. From 16 to 18 September, the platform showcases its brand strength, deepens affiliate connections, and outlines its plans for global expansion. BetFury continues to play a role in the evolving crypto and iGaming partnership landscape. BetFury’s Participation at SBC Summit The SBC Summit gathers over 25,000 delegates, including 6,000+ affiliates — the largest concentration of affiliate professionals in iGaming. For BetFury, this isn’t just visibility, it’s a strategic chance to present its Affiliate Program to the right audience. Face-to-face meetings, dedicated networking zones, and affiliate-focused sessions make Lisbon the ideal ground to build new partnerships and strengthen existing ones. BetFury Meets Affiliate Leaders at its Massive Stand BetFury arrives at the summit with a massive stand placed right in the center of the Affiliate zone. Designed as a true meeting hub, the stand combines large LED screens, a sleek interior, and the best coffee at the event — but its core mission goes far beyond style. Here, BetFury’s team welcomes partners and affiliates to discuss tailored collaborations, explore growth opportunities across multiple GEOs, and expand its global Affiliate Program. To make the experience even more engaging, the stand also hosts: Affiliate Lottery — a branded drum filled with exclusive offers and personalized deals for affiliates. Merch Kits — premium giveaways to boost brand recognition and leave visitors with a lasting conference memory. Besides, at SBC Summit Lisbon, attendees have a chance to meet the BetFury team along…
Share
BitcoinEthereumNews2025/09/18 01:20
Trump's border chief insists Americans support ICE – and is shut down by host: 'Come on!'

Trump's border chief insists Americans support ICE – and is shut down by host: 'Come on!'

Border Patrol Chief Greg Bovino was shut down Friday during an appearance on NewsNation after suggesting that federal immigration officials enjoyed widespread support
Share
Rawstory2026/01/23 22:36
Top 7 Managed IT Services for Legal Firms

Top 7 Managed IT Services for Legal Firms

If your practice management system went down at 3 p.m. on a filing deadline, how many people in your firm would know exactly what to do and who to call?  For most
Share
Techbullion2026/01/23 22:36