BlueMove DEX Loses 714,000 SUI to Cross-Version Reserve Desync Exploit
On July 11, 2026, an attacker drained approximately 714,000 SUI (around $528,000) from BlueMove DEX, a Sui-based automated market maker, within just 23 minutes. The stolen funds were quickly moved across a Wormhole bridge as USDC, and because the contracts were immutable, there was no way to freeze or patch them. BlueMove attributed the incident to an arithmetic overflow bug in a legacy contract, while a researcher at Quantum Void Labs suggested a suspicious function introduced in a May 31 upgrade played a role. An independent technical analysis found the actual cause to be a reserve desynchronization between two callable versions of the same package, where V1 and the latest version wrote different values to the reserve variable. This discrepancy allowed attackers to deflate the recorded reserve, inflate LP token minting ratios, and systematically empty the liquidity pools.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in