Cetus Protocol resumed full exchange and liquidity-pool operations at 03:00 UTC on June 8, 2025, 17 days after an exploit disrupted its concentrated-liquidity market maker on Sui. A contemporaneous report confirmed that swaps and liquidity-management functions were operating again after the restart.

The relaunch was consequential because it moved the incident from emergency containment into an operational recovery shaped by three unusual elements: a targeted Sui protocol intervention, direct financial support from Cetus and the Sui Foundation, and token-denominated compensation for losses that could not be restored immediately.

What returned on June 8

Cetus said users would again be able to swap assets, manage liquidity-provider positions, add or remove liquidity, and claim fees and rewards. The June 8 restart applied to the protocol’s previously disabled Sui liquidity pools; contemporaneous reporting said the exploit had not affected Cetus’s Aptos deployment.

The team reported that affected pools had been rebalanced and refilled before reopening. It described three sources of replacement liquidity: assets recovered through the Sui validator process, approximately $7 million in available Cetus cash reserves, and a 30 million USDC loan from the Sui Foundation.

Those figures should not be combined into a claim of complete dollar recovery. Cetus said affected pools reopened with between 85% and 99% of their former liquidity, depending on the damage to each pool. That was a protocol-reported pool-level range, not an independently audited recovery percentage for every user account.

Compensation did not equal immediate restoration

Cetus allocated 15% of the total CETUS token supply to a compensation contract. Its plan said 5% of the supply would be claimable at the relaunch, while another 10%—described as the team’s remaining unvested allocation—would unlock linearly over 12 months beginning June 10, 2025.

The distinction between restored assets and token compensation mattered. A CETUS allocation carried token-price and liquidity risk and was not equivalent to receiving the missing underlying assets immediately. Position NFTs associated with affected liquidity positions were to serve as certificates for compensation claims, including after the underlying liquidity had been withdrawn.

Cetus also said it had initiated legal action in multiple jurisdictions to pursue assets that remained outside the recovery process. That was a contemporaneous claim about enforcement activity, not evidence that further funds would necessarily be recovered.

Recovery required a targeted network intervention

The Sui Foundation’s official record shows that validators representing 90.9% of eligible stake supported a proposal to retrieve assets frozen in two attacker-controlled accounts. The Foundation’s own stake was excluded from the vote.

The approved mechanism permitted a designated address to act for the two accounts only in two predetermined recovery transactions. Recovered assets were placed under a four-of-six multisignature arrangement involving Cetus, the Sui Foundation and security auditor OtterSec.

This was not a reversal of Sui’s chain history. It was nevertheless a protocol-level exception that allowed transfers without the attacker’s signatures. The episode therefore raised a durable governance question: whether narrowly scoped intervention to recover exploited assets strengthens user protection or weakens expectations that control of a valid private key is final.

The patched code was only part of the test

Cetus’s incident account attributed the exploit to an incorrect overflow check in an open-source arithmetic library used by its liquidity calculations. The project’s GitHub release history records two `checked_shlw` fixes on May 22 and an additional library release on June 6.

A repository patch verifies that code changed; it does not independently prove that every deployed contract, recovery calculation or monitoring system was secure on June 8. Cetus said its fixes and compensation contracts had been audited and promised further audits, real-time monitoring, rate limits and a redesigned bounty program.

The defensible event-day conclusion is therefore bounded. Cetus restored core functionality on June 8 and returned substantial liquidity to affected pools, but the restart did not erase the uncompensated shortfalls, token-denominated repayment risk, unresolved asset recovery or governance controversy created by the May 22 exploit.

Primary sourceCetus Protocol — Relaunch recovery plan and June 8 schedule

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.