Scallop, a lending protocol built in the Sui ecosystem, has disclosed a security incident that resulted in the loss of roughly 150,000 SUI. According to the project, the issue was traced to a vulnerability in a contract connected to its sSUI rewards fund. The affected contract has since been frozen in an effort to prevent any further exploitation.
Incident limited to the sSUI rewards fund
Scallop said the breach did not affect its core protocol contracts. The team stated that the impact was confined to the sSUI rewards fund, while other reward funds remain intact. That distinction is important for users and the broader market, as it suggests the exploit targeted a specific rewards-related component rather than the protocol’s main lending infrastructure.
Team promises full reimbursement
To address user concerns, Scallop said it will provide 100% compensation for the losses tied to the incident. The protocol also noted that additional updates will be shared as more information becomes available. In DeFi, rapid containment measures, clear communication on the scope of impact, and a reimbursement plan are often key to maintaining community confidence after a security event.
Security scrutiny returns to Sui DeFi
The incident adds to ongoing concerns around smart contract security in emerging blockchain ecosystems. Even when a protocol’s core contracts remain unaffected, vulnerabilities in incentive modules and peripheral reward mechanisms can still create meaningful losses. Market participants will now be watching for more detail from Scallop on the exploit, the compensation process, and any new safeguards introduced after the attack.

