Another DeFi Exploit Drains 150,000 SUI From Scallop’s Deprecated Contract

Source Beincrypto

Scallop, a money market on Sui Network, lost about 150,000 SUI on Sunday after an attacker drained a deprecated rewards contract tied to the protocol’s sSUI spool.

The team froze the affected contract within minutes and pledged full reimbursement from its treasury. Core operations resumed in under two hours.

Another Sui Exploit Hits Peripheral Code, Not the Core Protocol

Scallop disclosed the incident at 12:50 UTC on April 26 through a public notice on X. The attacker targeted a side contract powering rewards for the sSUI spool. That spool is the protocol’s incentive layer for SUI depositors.

The affected contract was frozen immediately, according to the team. Core lending and borrowing pools stayed untouched. User deposits remained safe across every other Scallop market.

Two hours later, Scallop confirmed the freeze had been lifted on the core contracts. Withdrawals and deposits resumed at 14:42 UTC.

Most users on the Sui network were unaffected by the morning’s events.

“Scallop will fully cover 100% of the loss,” the money market articulated.

Stale Package Code From 2023 Sat Behind the Exploit

Independent on-chain analysis points to a deprecated V2 spool package as the entry point. Scallop published the code in November 2023, more than 17 months before the attack. On Sui, deployed packages are immutable. Old versions stay callable unless explicitly version-gated.

The bug centered on an uninitialized last_index counter, which tracks accumulated rewards for stakers. The attacker staked roughly 136,000 sSUI to exploit it.

This math treated the position as if it had existed since the spool launched in August 2023.

The spool index had grown to about 1.19 billion over 20 months. That allowed the exploiter to harvest around 162 trillion reward points. Those redeemed one-to-one for 150,000 SUI from the rewards pool.

The transaction hash 6WNDjCX3W852hipq6yrHhpUaSFHSPWfTxuLKaQkgNfVL captures the on-chain proof of the drain.

A Familiar Pattern Across Sui DeFi

The incident follows a string of Sui exploits in recent weeks. Volo Protocol lost roughly $3.5 million earlier this month in a similar peripheral incident. Each case targeted side contracts rather than core protocol logic.

It also lands one week after a major bridge incident on Ethereum, which produced roughly $292 million in unbacked liquid restaking tokens. Both attacks happened over weekends, when liquidity is thin and response times can lag.

Neither the Sui Foundation nor Mysten Labs has made a public statement on the matter.

For Scallop, however, the financial damage looks contained. The protocol confirmed it will absorb the entire loss without diluting user yields.

The team has not released a full post-mortem yet, with a prospective publishing of a complete audit of every remaining legacy package likely to shape the broader Sui DeFi response.

The deeper question is how Sui builders should manage immutable code and forgotten attack surfaces.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Bitcoin Nears $80,000: Two Scenarios That May Decide Q2—Bulls Or Bears?Bitcoin (BTC) is approaching a critical juncture as it presses against its nearest resistance wall at $80,000, which, according to some analysts, if not cleared, may send BTC back below $70,000.  
Author  NewsBTC
Apr 24, Fri
Bitcoin (BTC) is approaching a critical juncture as it presses against its nearest resistance wall at $80,000, which, according to some analysts, if not cleared, may send BTC back below $70,000.  
placeholder
Dogecoin Social Buzz Just Collapsed: Here’s What The Data ShowsDogecoin’s social momentum has fallen off sharply, and the rest of the market data suggests that the memecoin’s latest phase is being driven more by derivatives positioning than by any broad
Author  NewsBTC
Apr 24, Fri
Dogecoin’s social momentum has fallen off sharply, and the rest of the market data suggests that the memecoin’s latest phase is being driven more by derivatives positioning than by any broad
placeholder
Intel beat Wall Street in Q1 with $13.58 billion in revenue and $0.29 adjusted EPSIntel came into Thursday with a lot to prove and left with a much louder number set. The chipmaker posted first-quarter results that beat what Wall Street had penciled in, and traders pushed INTC shares up 15% in after-hours trading right after the release. Intel reported $13.58 billion in revenue for the quarter, above the […]
Author  Cryptopolitan
Apr 24, Fri
Intel came into Thursday with a lot to prove and left with a much louder number set. The chipmaker posted first-quarter results that beat what Wall Street had penciled in, and traders pushed INTC shares up 15% in after-hours trading right after the release. Intel reported $13.58 billion in revenue for the quarter, above the […]
placeholder
Tesla stock drops as the company raised its 2026 capex plan to $25 billion from $20 billionTesla stock is falling today because investors are dealing with rising spending, merger talk, and a market that chases big stories when numbers look weak. After earnings on Wednesday, the stock moved lower as traders focused on a spending plan that came in bigger than expected. Tesla raised its full-year capex target to $25 billion […]
Author  Cryptopolitan
Apr 24, Fri
Tesla stock is falling today because investors are dealing with rising spending, merger talk, and a market that chases big stories when numbers look weak. After earnings on Wednesday, the stock moved lower as traders focused on a spending plan that came in bigger than expected. Tesla raised its full-year capex target to $25 billion […]
placeholder
Bitcoin’s $80,000 Target Remains Elusive Amid New US-China TensionsBitcoin (BTC) traded near $78,000 on Thursday but continued to face resistance at the $80,000 level as fresh US-China friction weighed on risk sentiment.The White House accused Chinese entities of run
Author  Beincrypto
Apr 24, Fri
Bitcoin (BTC) traded near $78,000 on Thursday but continued to face resistance at the $80,000 level as fresh US-China friction weighed on risk sentiment.The White House accused Chinese entities of run
goTop
quote