OFICIAL Sui Blog

Security Should Follow Value: How Sui Thinks About Onchain Risk

What happened
Based on Sui Blog · Sep 17, 2026

Sui outlines a continuous security model that adapts to evolving protocols and shifting risk, emphasizing dependency tracking and post-deployment monitoring to address incidents in DeFi ecosystems.

Security Should Follow Value: How Sui Thinks About Onchain Risk
Sui Blog — Sui
Key points
·
Sui Foundation allocated $10 million to subsidize audits, formal verification, and bug bounties after Summer 2025 DeFi incidents.
·
Security risks extend beyond code vulnerabilities to include permissions, governance, and data feed integrity in interconnected DeFi systems.
·
Sui’s tools trace dependencies and value accumulation to prioritize risk assessment based on potential ecosystem impact.
Key numbers
·
To address risks identified in Summer 2025 DeFi incidents, the Sui Foundation established a $10 million fund to support ecosystem security.

Traditional onchain security focuses on audits at launch, but this approach fails to address evolving protocols, changing permissions, and new dependencies that emerge after deployment. Incidents in DeFi, including on Sui, have exposed vulnerabilities in shared code and administrative access rather than contract logic, highlighting the need for ongoing security assessments. Continuous evaluation of every system change is required to mitigate risks as applications grow in complexity and value, ensuring attention remains focused on the most critical points of exposure.

To address risks identified in Summer 2025 DeFi incidents, the Sui Foundation established a $10 million fund to support ecosystem security. The fund subsidizes builder audits, formal verification, increased bug bounties, and enhanced shared monitoring tools. The next phase involves transforming these investments into accessible infrastructure and tools that builders can use both before and after deployment to proactively manage risk.

DeFi applications rely on interconnected components such as price feeds, transaction routers, and shared libraries, making their security dependent on trusted external systems. Risks extend beyond code vulnerabilities to include overly broad permissions, compromised governance, and stale or incorrect data feeds. Composability, a core strength of DeFi, also expands the attack surface, as each new dependency introduces potential failure points that individual teams may not fully understand.

Sui’s security tools aim to trace dependencies, track value accumulation, and identify widely used code to prioritize risk assessment based on potential impact rather than uniform scrutiny. These tools provide builders with actionable insights without imposing approval authority, while infrastructure-level enforcement remains critical for autonomous systems. The approach emphasizes current, structured, and version-specific security evidence to support informed decision-making across the ecosystem.

Original source → Deals on Clipraptor.com →