Another DeFi Exploit Drains 150,000 SUI From Scallop’s Deprecated Contract

Source Beincrypto

Scallop, a money market on Sui Network, lost about 150,000 SUI on Sunday after an attacker drained a deprecated rewards contract tied to the protocol’s sSUI spool.

The team froze the affected contract within minutes and pledged full reimbursement from its treasury. Core operations resumed in under two hours.

Another Sui Exploit Hits Peripheral Code, Not the Core Protocol

Scallop disclosed the incident at 12:50 UTC on April 26 through a public notice on X. The attacker targeted a side contract powering rewards for the sSUI spool. That spool is the protocol’s incentive layer for SUI depositors.

The affected contract was frozen immediately, according to the team. Core lending and borrowing pools stayed untouched. User deposits remained safe across every other Scallop market.

Two hours later, Scallop confirmed the freeze had been lifted on the core contracts. Withdrawals and deposits resumed at 14:42 UTC.

Most users on the Sui network were unaffected by the morning’s events.

“Scallop will fully cover 100% of the loss,” the money market articulated.

Stale Package Code From 2023 Sat Behind the Exploit

Independent on-chain analysis points to a deprecated V2 spool package as the entry point. Scallop published the code in November 2023, more than 17 months before the attack. On Sui, deployed packages are immutable. Old versions stay callable unless explicitly version-gated.

The bug centered on an uninitialized last_index counter, which tracks accumulated rewards for stakers. The attacker staked roughly 136,000 sSUI to exploit it.

This math treated the position as if it had existed since the spool launched in August 2023.

The spool index had grown to about 1.19 billion over 20 months. That allowed the exploiter to harvest around 162 trillion reward points. Those redeemed one-to-one for 150,000 SUI from the rewards pool.

The transaction hash 6WNDjCX3W852hipq6yrHhpUaSFHSPWfTxuLKaQkgNfVL captures the on-chain proof of the drain.

A Familiar Pattern Across Sui DeFi

The incident follows a string of Sui exploits in recent weeks. Volo Protocol lost roughly $3.5 million earlier this month in a similar peripheral incident. Each case targeted side contracts rather than core protocol logic.

It also lands one week after a major bridge incident on Ethereum, which produced roughly $292 million in unbacked liquid restaking tokens. Both attacks happened over weekends, when liquidity is thin and response times can lag.

Neither the Sui Foundation nor Mysten Labs has made a public statement on the matter.

For Scallop, however, the financial damage looks contained. The protocol confirmed it will absorb the entire loss without diluting user yields.

The team has not released a full post-mortem yet, with a prospective publishing of a complete audit of every remaining legacy package likely to shape the broader Sui DeFi response.

The deeper question is how Sui builders should manage immutable code and forgotten attack surfaces.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Semiconductor Sector Continues to Rise, Should Retail Investors Buy Intel or AMD? On April 23, Eastern Time, Intel (INTC) reported its latest quarterly earnings results, showing that revenue grew 7% to $13.6 billion and earnings per share was $0.29, beating expectation
Author  TradingKey
Apr 24, Fri
On April 23, Eastern Time, Intel (INTC) reported its latest quarterly earnings results, showing that revenue grew 7% to $13.6 billion and earnings per share was $0.29, beating expectation
placeholder
Gold drops below $4,700 on stronger US Dollar, Middle East tensions Gold price (XAU/USD) falls to around $4,690 during the early Asian session on Friday. The precious metal attracts some sellers amid a stronger US Dollar (USD) and elevated oil prices that stoked inflation worries. 
Author  FXStreet
Apr 24, Fri
Gold price (XAU/USD) falls to around $4,690 during the early Asian session on Friday. The precious metal attracts some sellers amid a stronger US Dollar (USD) and elevated oil prices that stoked inflation worries. 
placeholder
Silver Price Forecast: XAG/USD plummets below $76 as oil price posts fresh weekly highSilver price (XAG/USD) is down almost 2.3% to near $76.00 during the European trading session on Thursday. The white metal faces selling pressure as oil prices extends its winning streak for the third trading day on Thursday.
Author  FXStreet
Apr 23, Thu
Silver price (XAG/USD) is down almost 2.3% to near $76.00 during the European trading session on Thursday. The white metal faces selling pressure as oil prices extends its winning streak for the third trading day on Thursday.
placeholder
WTI sticks to positive bias above $92.00 amid Middle East tensionsWest Texas Intermediate (WTI) – the benchmark US Crude Oil price – fades an Asian session spike to the $95.80-$95.85 area, or a one-and-a-half-week top, and retreats to the lower end of its daily range in the last hour.
Author  FXStreet
Apr 23, Thu
West Texas Intermediate (WTI) – the benchmark US Crude Oil price – fades an Asian session spike to the $95.80-$95.85 area, or a one-and-a-half-week top, and retreats to the lower end of its daily range in the last hour.
placeholder
JPMorgan Raises S&P 500 Target; Can AI Sector Continue to Drive US Stocks?JPMorgan Chase has raised its year-end target for the S&P 500, noting that the core driver is not a simple recovery in sentiment, but rather upward earnings revisions for AI-related techn
Author  TradingKey
Apr 22, Wed
JPMorgan Chase has raised its year-end target for the S&P 500, noting that the core driver is not a simple recovery in sentiment, but rather upward earnings revisions for AI-related techn
goTop
quote