BlueMove says an attacker exploited a legacy smart-contract flaw to drain roughly 700,000 SUI, or about $500,000, from locked liquidity pools on its decentralized exchange. The incident has prompted online accusations of an insider role, which the project disputes as it offers the exploiter a 30% bounty to return the funds.

Attack and initial accusations

The draining was flagged over the weekend by Quantum Void Labs founder Tyler Simpson, who shared screenshots that appeared to show more than 700,000 SUI being removed from BlueMove’s locked liquidity pools. Simpson first accused the platform itself of draining the funds and suggested the activity amounted to a crime.

He later revised that view and said BlueMove had been exploited. The following day, however, he argued that the project had effectively “shipped the backdoor themselves” by implementing a package on May 31 that, in his view, prepared the conditions for the exploit. According to Simpson, that update introduced immutable functions including “add_liquidity_returns” and “double-mint LP inflation,” while the eventual exploit began more than 40 days later.

BlueMove’s explanation

BlueMove rejects the suggestion that it deliberately enabled the drain. In a statement on its website, the project said the loss was caused by an attacker exploiting “a long-standing arithmetic overflow bug in BlueMove’s legacy AMM contract to drain liquidity from 389 pools.”

The project said the bug had reportedly been visible since at least 2023. It added that a subsequent upgrade failed to address the issue and in practice made later fixes impossible. BlueMove said that because the UpgradeCap was burned on June 3, it no longer has an on-chain route to patch or disable the vulnerable v1 package.

According to BlueMove, remediation would now require either an independent admin or freeze capability, if one exists outside the UpgradeCap, or a full migration to a new audited package.

Bounty offer and user compensation

BlueMove said it sent an on-chain message to a crypto address in an attempt to reach the attacker. In that message, it offered to let the exploiter keep 30% of the proceeds as a white hat bounty if 70% is returned within 48 hours to a Sui address controlled by the project.

The team said it would consider the matter resolved if the funds are returned. If not, it said it would pursue available legal and recovery options. Based on the project’s estimate of roughly $500,000 in drained SUI, the proposed bounty would be about $150,000 if the token valuation remains similar.

BlueMove also said it will compensate affected users if the attacker does not respond within the 48-hour window. At the time of writing in the source report, the project said the attacker had just over 12 hours left to answer the offer.

Operations suspended, shutdown planned

The exchange said its operations remain suspended while it investigates the incident. It also said the project will shut down going forward.

A spokesperson for the SUI Network declined to comment when asked about the drain and any effort to recover the funds.

The episode leaves several issues unresolved: whether the exploit stemmed solely from a known coding flaw, as BlueMove says, or whether the contract changes highlighted by outside observers played a more direct role. For now, the confirmed facts are that 389 pools were affected, roughly 700,000 SUI was drained, and BlueMove has promised reimbursement if its recovery effort fails.

Source: protos.com