Bluefin; Reviewed & Scored | The Block Note
DEX Review · Updated August 2026

Bluefin:
Sui's leading DEX, genuinely well-secured but shrinking, in the shadow of a neighbor's $223 million hack.

We tore apart Bluefin, a spot and perpetuals DEX built on Sui since 2023, across the same seven-category scorecard we've used throughout this series, the first Sui-based platform we've reviewed. From genuinely extensive audit coverage across six named firms (Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, and OtterSec), disclosed, credible institutional backing (Polychain, SIG, Brevan Howard, Tower Research), and genuinely modern, frictionless onboarding via 1-click zkLogin and gasless trading, to real, honest concerns worth centering directly: DefiLlama's current, most directly-sourced figure shows TVL at $20.25 million, down 20.1% over the past 30 days and dramatically smaller than an older $109.9 million figure from January 2025, and a genuinely important adjacent finding: following the May 2025, $223 million hack of Cetus Protocol, a different Sui-based DEX with a similar concentrated-liquidity design, independent security researchers specifically examined Bluefin's comparable architecture as a cautionary exercise, a real, adjacent concern distinct from Bluefin itself being hacked; and landed on a score the marketing page won't show you.

Type Decentralized Exchange (Sui spot AMM + perpetuals) Platforms Web · Sui wallet · zkLogin (Google) Fees Dynamic funding rates; disclosed fee/revenue split Discount Offer None
bluefin
DEX
First Sui platform in this series
6 named audit firms · TVL down 20.1% (30d)

Our take, up front: Bluefin, built on Sui since 2023, is the first Sui-native platform we've reviewed in this series, combining spot trading through a concentrated-liquidity AMM with perpetual derivatives, aiming for a CEX-like experience through an off-chain orderbook with on-chain settlement. Real, genuinely credible, disclosed institutional backing: Polychain, SIG, Brevan Howard, and Tower Research, with liquidity support from named market makers including Wintermute, Amber, and Keyrock. Real, genuinely extensive, multi-firm audit coverage: Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, and OtterSec, six named firms, among the most extensively audited platforms we've found in this series. Real, genuinely sophisticated security operations beyond audits alone: real-time threat monitoring via Guardrail, and a risk engine designed and monitored with Chaos Labs, backed by an active bug bounty program via HackenProof. Real, genuinely distinctive, modern onboarding: 1-click zkLogin via Google account and gasless trading, described directly as making onboarding frictionless for both new and experienced users. Real, disclosed, precise fee and revenue figures: $148,149 in fees over the past 30 days, with an annualized run-rate around $19.24 million in fees and $6.99 million in protocol revenue. What we can't set aside: a real, honest, notable decline and discrepancy across our sources. DefiLlama's current, most directly-sourced figure shows $20.25 million in TVL, down 20.1% over the past 30 days, dramatically smaller than an older, January 2025 figure of $109.9 million cited elsewhere; we're weighting the current, direct figure most heavily. Real, honest, disclosed centralization point: Bluefin's own bug bounty scope explicitly treats its sequencer as a trusted party, meaning issues from sequencer misbehavior fall outside the program's coverage. Real, genuinely important, adjacent security context worth presenting with real precision: following the May 22, 2025 hack of Cetus Protocol, a different Sui-based DEX, for $223 million, at least one detailed independent security analysis examined Bluefin's similarly-designed concentrated-liquidity architecture specifically because of that architectural similarity, concluding that even well-designed protocols can harbor subtle vulnerabilities; this was a third-party cautionary analysis, not a confirmed Bluefin exploit, and we found no disclosed hack specific to Bluefin itself. We weighted all of it below.

Real, genuinely extensive, multi-firm audits: Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, and OtterSec, six named firms, among the most extensively audited platforms we've found in this series. Real, genuinely sophisticated, disclosed security operations beyond audits alone: real-time threat monitoring via Guardrail, and a risk engine designed and monitored with Chaos Labs. Real, an active bug bounty program via HackenProof. Real, no confirmed hack or exploit specific to Bluefin itself found in our research. Real, honest, disclosed trust assumption: Bluefin's bug bounty scope explicitly treats its sequencer as a trusted party, meaning issues from sequencer misbehavior fall outside the program's coverage. Real, genuinely important, adjacent context worth noting precisely: following the May 2025, $223 million hack of Cetus Protocol, a different Sui-based DEX, at least one detailed independent security analysis examined Bluefin's similarly-designed concentrated-liquidity architecture specifically because of that architectural similarity, concluding that even well-designed protocols can harbor subtle vulnerabilities; this was a third-party cautionary analysis, not a confirmed Bluefin exploit.

Why this scores above the midpoint: genuinely extensive, multi-firm audits and sophisticated, disclosed security monitoring are real strengths, tempered by a disclosed sequencer trust assumption and a real, adjacent architectural-similarity concern raised by independent researchers following a comparable platform's hack.

Pros

  • Six named audit firms (Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, OtterSec)
  • Real-time threat monitoring (Guardrail) and a Chaos Labs-monitored risk engine
  • No confirmed hack specific to Bluefin itself found in our research

Cons

  • Sequencer explicitly treated as a trusted party, outside bug-bounty scope
  • Independent researchers flagged Bluefin's architectural similarity to the hacked Cetus Protocol

Real, genuinely credible, disclosed liquidity support from named institutional market makers: Wintermute, Amber, and Keyrock. Real, honest, notable discrepancy and decline across our sources: DefiLlama's current, most directly-sourced figure shows $20.25 million in TVL, down 20.1% over the past 30 days, while an older (January 2025) source cited $109.9 million, and a separate source cited roughly $84 million; we're weighting the current DefiLlama figure most heavily given its direct sourcing and recency. Real, disclosed, precise fee and revenue figures: $148,149 in fees over the past 30 days, with an annualized run-rate around $19.24 million in fees and $6.99 million in protocol revenue.

Why this scores below the midpoint: genuinely credible institutional market-making support is a real positive, tempered by an honest, notable decline in current, directly-sourced TVL relative to the platform's own reported history.

Pros

  • Credible, disclosed institutional market-making support (Wintermute, Amber, Keyrock)
  • Disclosed, precise fee and revenue figures

Cons

  • Current TVL ($20.25M) down 20.1% over 30 days and far below an older $109.9M figure

Real, genuinely non-custodial trading architecture. Real, disclosed, credible institutional backing: Polychain, SIG, Brevan Howard, and Tower Research. Real, partially disclosed leadership background, described as coming from companies including Meta and Goldman Sachs, though without the fully named, individual-level founder disclosure we've found at some other platforms in this series. Real, honest, disclosed centralization point: the platform's sequencer is explicitly treated as a trusted party in its own bug bounty scope.

Why this scores above the midpoint: genuinely credible, disclosed institutional backing is a real positive, tempered by partial rather than fully individual-level founder disclosure and an honest, disclosed sequencer trust assumption.

Pros

  • Genuinely non-custodial; disclosed, credible institutional backing

Cons

  • Partial (background-only) rather than fully named, individual-level founder disclosure
  • Disclosed sequencer trust assumption is a real, honest centralization point

Real, genuinely broad product integration: spot trading via AMM, perpetual derivatives, and liquidity pools, all on one platform. Real, cross-chain bridging via Wormhole integration. Real, honest, notable detail: while Bluefin technically operates on both Arbitrum and Sui, Sui holds effectively 100% of current activity per DefiLlama, meaning the Arbitrum deployment is negligible in practice today.

Why this scores well: a genuinely broad product suite and real cross-chain bridging capability, tempered by the honest reality that the platform's multi-chain claim reflects one dominant, active chain today.

Pros

  • Spot AMM, perpetuals, and liquidity pools in one integrated platform
  • Wormhole cross-chain bridging

Cons

  • Arbitrum deployment is negligible in practice; effectively 100% of activity is on Sui

Real, genuinely distinctive, modern onboarding: 1-click zkLogin via Google account and gasless trading, described directly as making onboarding frictionless for both new and experienced users. Real, described as delivering a CEX-like trading experience through an off-chain orderbook with on-chain settlement.

Why this scores well: genuinely distinctive, modern onboarding features and a CEX-like trading experience are real, substantive strengths.

Pros

  • 1-click zkLogin (Google) and gasless trading genuinely reduce onboarding friction
  • CEX-like execution experience via off-chain orderbook, on-chain settlement

Cons

  • Not available to United States residents, a real, disclosed access limitation

Real, disclosed, precise fee and revenue figures, with dynamic perpetual funding rates shifting with market sentiment. Real, genuinely distinctive rewards program, Blue Points and SUI token rewards for platform activity and fee payment.

Why this scores above the midpoint: a disclosed, functioning fee model with a real, genuine rewards program layered on top.

Pros

  • Disclosed, precise fee and revenue figures
  • Blue Points and SUI token rewards program for activity and fees paid

Cons

  • Dynamic funding rates on perpetuals add variable cost beyond stated fees

Real, genuinely distinctive zkLogin onboarding and gasless trading. Real, Wormhole cross-chain bridging. Real, sophisticated security operations (Guardrail monitoring, Chaos Labs risk engine) that also function as genuine user-facing extras worth noting.

Pros

  • Distinctive zkLogin onboarding; Wormhole bridging; sophisticated risk monitoring

Cons

  • None significant found in our research
Where to get it

Access only through Bluefin's official app, and confirm you're not accessing it from a restricted jurisdiction.

Given the platform's architectural similarity to Cetus Protocol's concentrated-liquidity design, treat any large single position with the same caution you'd apply to any concentrated-liquidity AMM, and keep an eye on official security advisories.

0/ 100

A genuinely well-secured platform, honestly shrinking in the shadow of a neighbor's hack.

Bluefin earns real credit for taking security seriously in a way we can actually verify: six named audit firms, real-time monitoring, a disclosed risk engine, and credible, disclosed institutional backing are all genuine, substantive positives, and we found no confirmed hack of Bluefin itself. We also think it's important to be direct about two things most sources didn't dwell on. First, the platform's own most current, directly-sourced TVL figure is down sharply both month-over-month and relative to its own reported history from just over a year ago, a real, honest signal worth taking seriously rather than glossing over with an older, more flattering number. Second, when a neighboring, architecturally similar Sui DEX suffered one of the largest hacks we've documented anywhere in this project, independent researchers thought Bluefin's own design was similar enough to warrant a dedicated look. That's not the same as Bluefin having been hacked, and we want to be precise about that distinction, but it's also not nothing, and we think a fair review says so plainly.

Best forSui-native traders who want extensively audited infrastructure and a genuinely modern, frictionless onboarding experience
Not forUS residents, or traders prioritizing the deepest, most stable liquidity over the platform's other genuine strengths
Score Ledger
bluefin · 7 line items
01Security21.0
02Liquidity10.0
03Decentralization9.0
04Assets6.5
05UX8.0
06Fees6.5
07Extras3.75
TOTAL64.75
≈ 65 / 100; Well-secured, honestly shrinking

The scorecard above is deliberately general. Whether Bluefin is right for you depends heavily on which of these you already are.

Best fit

The Sui-native trader who wants extensively audited infrastructure and a genuinely modern, frictionless onboarding flow

This is genuinely where Bluefin's real strengths concentrate most heavily.

Good fit

The trader specifically interested in Bluefin's disclosed, credible institutional backing and market-making support

Named backers and market makers are a real, verifiable trust signal worth weighing directly.

Workable fit

The user who follows Bluefin's official security advisories given its architectural similarity to a hacked neighbor

Given the real, adjacent concern researchers raised, this awareness is a genuinely reasonable step here specifically.

Poor fit

US residents, or traders prioritizing the deepest, most stable liquidity above the platform's other strengths

The disclosed geofencing and the honest recent TVL decline make this a real, honest consideration.

The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the Cetus-adjacent security analysis explained precisely, TVL's trajectory presented transparently, the audit and security-operations roster, and Bluefin against the full field, closing out this batch of reviews.

The Cetus-adjacent security analysis, precisely

Detail
What happened to CetusCetus Protocol, a different Sui-based DEX, was hacked for $223 million on May 22, 2025
Why Bluefin was examinedBluefin Spot uses a similarly-designed concentrated-liquidity architecture
What the analysis foundNo confirmed vulnerability in Bluefin; a cautionary examination given the architectural similarity
Was Bluefin hacked?No; we found no disclosed exploit specific to Bluefin itself

We're presenting this distinction carefully: an independent researcher raising a caution based on architectural similarity is real and worth knowing, but it is not the same as a confirmed exploit, and we don't want to blur that line either direction.

TVL, presented transparently

SourceFigure cited
DefiLlama (current)$20.25 million, down 20.1% over the past 30 days
Backpack Exchange learn article"$84M+"
Gate Learn (Jan 2025 reference date)$109.9 million

We're weighting DefiLlama's current, directly-sourced, dated figure most heavily; the honest takeaway is a real, notable decline over time rather than a stable, sustained figure.

Audits and security operations

LayerDetail
Named audit firmsTrail of Bits, Halborn, Quantstamp, PeckShield, Hacken, OtterSec (six total)
Real-time monitoringGuardrail threat monitoring system
Risk engineDesigned and monitored with Chaos Labs
Bug bountyActive program via HackenProof
Disclosed trust assumptionSequencer treated as a trusted party; explicitly out of bug-bounty scope

This is a genuinely layered, multi-part security approach, among the most comprehensive we've documented in this series, with one honestly disclosed centralization exception in the sequencer.

Bluefin against the full field

BluefinOrcaHyperliquid
ChainSui (primary)SolanaOwn L1
Named audit firmsSixFourThree
Confirmed security incidentsNone foundNone foundNone (JELLY was governance)
Distinctive featurezkLogin onboarding; multi-layer security opsOcean-conservation fee allocationDominant liquidity

Bluefin's disclosed-incident record sits alongside the cleanest platforms we've reviewed in this entire series, even accounting for the real, adjacent Cetus-related caution we've detailed above.

We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We've excluded Bluefin's own official site and one specialized, security-focused technical analysis (not a general review) from this comparison.

The Block Note (us)N/A / 100
Industry averageN/A / 100

Our score lands modestly below the aggregated industry average; most general sources describe Bluefin's security investment and backing favorably without directly grappling with the recent TVL decline or the Cetus-adjacent architectural caution the way our methodology does.

SourceScoreType

Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.

No confirmed hack or exploit specific to Bluefin itself was found in our research. Following the May 2025 hack of a different, architecturally similar Sui DEX (Cetus Protocol), independent researchers examined Bluefin's design as a precaution, but did not confirm an actual vulnerability or breach.

Cetus Protocol, a separate, unrelated DEX on Sui, was hacked for $223 million on May 22, 2025. Because Bluefin Spot uses a similar concentrated-liquidity architecture, independent security researchers examined Bluefin specifically to see if similar risks might apply, as a cautionary exercise rather than in response to any actual incident at Bluefin.

Primarily Sui, since 2023. It technically also operates on Arbitrum, but per DefiLlama, Sui accounts for effectively 100% of current activity.

DefiLlama's current, directly-sourced figure is $20.25 million, down 20.1% over the past 30 days and dramatically smaller than an older, January 2025 figure of $109.9 million cited elsewhere.

Disclosed institutional backers include Polychain, SIG, Brevan Howard, and Tower Research, with liquidity support from market makers including Wintermute, Amber, and Keyrock.

No, Bluefin explicitly discloses that it's not available to United States residents.

A Sui-native feature letting users log in with a familiar account, like Google, in one click, rather than manually managing a separate crypto wallet from the start, genuinely reducing onboarding friction.

Six named firms: Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, and OtterSec, among the most extensively audited platforms we've reviewed in this series.

Affiliate & editorial disclosure: This page may contain affiliate links. If you buy through one, we may earn a commission at no extra cost to you. That relationship does not influence the category weightings or scores above; those are set by our editorial methodology before any offer is placed. Decentralized exchanges reduce custodial risk but do not eliminate risk: smart-contract, bridge, oracle, validator, and market-structure risk remain real regardless of how "decentralized" a platform's marketing describes it as. Leverage trading can result in losses exceeding your initial deposit. Nothing here is financial advice.
Features, pricing, and security details verified against public sources as of Aug 2026; always confirm current terms directly with Bluefin.

More Reviews

raydium logo cover image

Raydium – DEX Review

Score: 68/100. Solana's liquidity leader, carrying two confirmed incidents and a real, wide gap in third-party security ratings.

Read More