Scallop, a Sui-native DeFi lending protocol, suffered an exploit tied to its sSUI rewards pool. Here is what happened, why it matters, and what to watch next.Scallop, a Sui-native DeFi lending protocol, suffered an exploit tied to its sSUI rewards pool. Here is what happened, why it matters, and what to watch next.

Scallop Exploit Hits sSUI Rewards Pool on Sui

2026/04/27 13:48
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Scallop, a DeFi lending protocol native to the Sui blockchain, suffered an exploit targeting its sSUI rewards pool. The incident, which involved a deprecated contract vulnerability, adds to a growing streak of DeFi security failures in April 2026.

What happened in the Scallop sSUI rewards pool exploit

The exploit struck Scallop’s sSUI rewards pool, a mechanism used to distribute staking incentives to protocol participants. According to reporting from Blockonomi, the vulnerability was tied to a deprecated contract that remained accessible on-chain.

Key Takeaways

  • Scallop’s sSUI rewards pool was exploited through a deprecated contract vulnerability.
  • The incident is part of a broader pattern of DeFi losses totaling $606 million in April 2026.
  • Users should monitor Scallop’s official channels for updates on fund safety and pool status.

Scallop operates as a lending and borrowing platform on Sui, allowing users to deposit assets and earn yield. The sSUI rewards pool specifically handles distribution of staking rewards tied to Sui’s native liquid staking token, as described in the protocol’s official documentation.

The exploit highlights a recurring problem in DeFi: deprecated smart contracts that are no longer actively maintained but remain callable on-chain. Even when a protocol upgrades its core logic, old contract addresses can persist as attack surfaces if not properly decommissioned.

Why this matters for Scallop users and Sui DeFi

For depositors and borrowers on Scallop, the immediate concern is whether funds beyond the rewards pool were affected. The protocol’s multi-pool architecture suggests the exploit may have been confined to the sSUI rewards mechanism rather than core lending markets.

The incident lands at a difficult moment for DeFi security broadly. April 2026 has seen a streak of exploits, with the sector losing $606 million across multiple protocols. For projects that have experienced significant DeFi losses this month, the pattern raises questions about audit coverage for legacy contracts.

Sui’s DeFi ecosystem has been growing steadily, attracting new protocols and liquidity over recent months. A security failure at one of the chain’s established lending platforms could slow that momentum, particularly as broader crypto market momentum builds and users evaluate where to deploy capital.

Rewards pools are core to user acquisition in DeFi lending. When the incentive layer itself is compromised, it undermines the value proposition that attracts liquidity in the first place, a dynamic familiar to anyone tracking how investor preferences are shifting across the digital asset space.

What to watch next after the Scallop exploit

Users with assets on Scallop should monitor the protocol’s official communication channels for a post-mortem detailing the exploit’s scope, the amount of funds affected, and steps being taken to prevent recurrence.

Key items to watch include whether Scallop will issue a formal incident report, whether affected users will receive compensation, and whether the deprecated contract has been fully neutralized.

Until a full accounting is available, users should exercise caution before interacting with Scallop’s rewards mechanisms. The status of core lending and borrowing pools, which operate through separate contracts, will also need confirmation from the team.

For the wider Sui ecosystem, the incident serves as a reminder that contract lifecycle management is as critical as initial audit coverage. As DeFi protocols mature and upgrade, ensuring that deprecated components are fully decommissioned remains an unsolved operational challenge.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

Roll the Dice & Win Up to 1 BTC

Roll the Dice & Win Up to 1 BTCRoll the Dice & Win Up to 1 BTC

Invite friends & share 500,000 USDT!