Aftermath Finance said a fee-logic flaw caused the Sui exploit, while GoPlus described abused admin access and a symbol mismatch bug; the protocol said users will be fully reimbursed with support from Mysten Labs and the Sui Foundation.
Aftermath Finance’s April 29 exploit on Sui resulted in losses initially reported at about $1.1 million in USDC, later described by the protocol as roughly $1.14 million and by newer reporting as exceeding $1.14 million. External analysis tied the incident to a fee accounting defect in the platform’s perpetuals system, while GoPlus said the attacker abused ADMIN access in add_integrator_config and exploited a symbol mismatch flaw in calculate_taker_fees to repeatedly extract tokens. Aftermath Finance said all affected users would be fully reimbursed, with support from Mysten Labs and the Sui Foundation, and stated that the issue stemmed from application fee logic rather than a broader problem with the Sui network.