Bluefin:
Sui's leading DEX, genuinely well-secured but shrinking, in the shadow of a neighbor's $223 million hack.
We tore apart Bluefin, a spot and perpetuals DEX built on Sui since 2023, across the same seven-category scorecard we've used throughout this series, the first Sui-based platform we've reviewed. From genuinely extensive audit coverage across six named firms (Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, and OtterSec), disclosed, credible institutional backing (Polychain, SIG, Brevan Howard, Tower Research), and genuinely modern, frictionless onboarding via 1-click zkLogin and gasless trading, to real, honest concerns worth centering directly: DefiLlama's current, most directly-sourced figure shows TVL at $20.25 million, down 20.1% over the past 30 days and dramatically smaller than an older $109.9 million figure from January 2025, and a genuinely important adjacent finding: following the May 2025, $223 million hack of Cetus Protocol, a different Sui-based DEX with a similar concentrated-liquidity design, independent security researchers specifically examined Bluefin's comparable architecture as a cautionary exercise, a real, adjacent concern distinct from Bluefin itself being hacked; and landed on a score the marketing page won't show you.
Our take, up front: Bluefin, built on Sui since 2023, is the first Sui-native platform we've reviewed in this series, combining spot trading through a concentrated-liquidity AMM with perpetual derivatives, aiming for a CEX-like experience through an off-chain orderbook with on-chain settlement. Real, genuinely credible, disclosed institutional backing: Polychain, SIG, Brevan Howard, and Tower Research, with liquidity support from named market makers including Wintermute, Amber, and Keyrock. Real, genuinely extensive, multi-firm audit coverage: Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, and OtterSec, six named firms, among the most extensively audited platforms we've found in this series. Real, genuinely sophisticated security operations beyond audits alone: real-time threat monitoring via Guardrail, and a risk engine designed and monitored with Chaos Labs, backed by an active bug bounty program via HackenProof. Real, genuinely distinctive, modern onboarding: 1-click zkLogin via Google account and gasless trading, described directly as making onboarding frictionless for both new and experienced users. Real, disclosed, precise fee and revenue figures: $148,149 in fees over the past 30 days, with an annualized run-rate around $19.24 million in fees and $6.99 million in protocol revenue. What we can't set aside: a real, honest, notable decline and discrepancy across our sources. DefiLlama's current, most directly-sourced figure shows $20.25 million in TVL, down 20.1% over the past 30 days, dramatically smaller than an older, January 2025 figure of $109.9 million cited elsewhere; we're weighting the current, direct figure most heavily. Real, honest, disclosed centralization point: Bluefin's own bug bounty scope explicitly treats its sequencer as a trusted party, meaning issues from sequencer misbehavior fall outside the program's coverage. Real, genuinely important, adjacent security context worth presenting with real precision: following the May 22, 2025 hack of Cetus Protocol, a different Sui-based DEX, for $223 million, at least one detailed independent security analysis examined Bluefin's similarly-designed concentrated-liquidity architecture specifically because of that architectural similarity, concluding that even well-designed protocols can harbor subtle vulnerabilities; this was a third-party cautionary analysis, not a confirmed Bluefin exploit, and we found no disclosed hack specific to Bluefin itself. We weighted all of it below.
Real, genuinely extensive, multi-firm audits: Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, and OtterSec, six named firms, among the most extensively audited platforms we've found in this series. Real, genuinely sophisticated, disclosed security operations beyond audits alone: real-time threat monitoring via Guardrail, and a risk engine designed and monitored with Chaos Labs. Real, an active bug bounty program via HackenProof. Real, no confirmed hack or exploit specific to Bluefin itself found in our research. Real, honest, disclosed trust assumption: Bluefin's bug bounty scope explicitly treats its sequencer as a trusted party, meaning issues from sequencer misbehavior fall outside the program's coverage. Real, genuinely important, adjacent context worth noting precisely: following the May 2025, $223 million hack of Cetus Protocol, a different Sui-based DEX, at least one detailed independent security analysis examined Bluefin's similarly-designed concentrated-liquidity architecture specifically because of that architectural similarity, concluding that even well-designed protocols can harbor subtle vulnerabilities; this was a third-party cautionary analysis, not a confirmed Bluefin exploit.
Pros
- Six named audit firms (Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, OtterSec)
- Real-time threat monitoring (Guardrail) and a Chaos Labs-monitored risk engine
- No confirmed hack specific to Bluefin itself found in our research
Cons
- Sequencer explicitly treated as a trusted party, outside bug-bounty scope
- Independent researchers flagged Bluefin's architectural similarity to the hacked Cetus Protocol
Real, genuinely credible, disclosed liquidity support from named institutional market makers: Wintermute, Amber, and Keyrock. Real, honest, notable discrepancy and decline across our sources: DefiLlama's current, most directly-sourced figure shows $20.25 million in TVL, down 20.1% over the past 30 days, while an older (January 2025) source cited $109.9 million, and a separate source cited roughly $84 million; we're weighting the current DefiLlama figure most heavily given its direct sourcing and recency. Real, disclosed, precise fee and revenue figures: $148,149 in fees over the past 30 days, with an annualized run-rate around $19.24 million in fees and $6.99 million in protocol revenue.
Pros
- Credible, disclosed institutional market-making support (Wintermute, Amber, Keyrock)
- Disclosed, precise fee and revenue figures
Cons
- Current TVL ($20.25M) down 20.1% over 30 days and far below an older $109.9M figure
Real, genuinely non-custodial trading architecture. Real, disclosed, credible institutional backing: Polychain, SIG, Brevan Howard, and Tower Research. Real, partially disclosed leadership background, described as coming from companies including Meta and Goldman Sachs, though without the fully named, individual-level founder disclosure we've found at some other platforms in this series. Real, honest, disclosed centralization point: the platform's sequencer is explicitly treated as a trusted party in its own bug bounty scope.
Pros
- Genuinely non-custodial; disclosed, credible institutional backing
Cons
- Partial (background-only) rather than fully named, individual-level founder disclosure
- Disclosed sequencer trust assumption is a real, honest centralization point
Real, genuinely broad product integration: spot trading via AMM, perpetual derivatives, and liquidity pools, all on one platform. Real, cross-chain bridging via Wormhole integration. Real, honest, notable detail: while Bluefin technically operates on both Arbitrum and Sui, Sui holds effectively 100% of current activity per DefiLlama, meaning the Arbitrum deployment is negligible in practice today.
Pros
- Spot AMM, perpetuals, and liquidity pools in one integrated platform
- Wormhole cross-chain bridging
Cons
- Arbitrum deployment is negligible in practice; effectively 100% of activity is on Sui
Real, genuinely distinctive, modern onboarding: 1-click zkLogin via Google account and gasless trading, described directly as making onboarding frictionless for both new and experienced users. Real, described as delivering a CEX-like trading experience through an off-chain orderbook with on-chain settlement.
Pros
- 1-click zkLogin (Google) and gasless trading genuinely reduce onboarding friction
- CEX-like execution experience via off-chain orderbook, on-chain settlement
Cons
- Not available to United States residents, a real, disclosed access limitation
Real, disclosed, precise fee and revenue figures, with dynamic perpetual funding rates shifting with market sentiment. Real, genuinely distinctive rewards program, Blue Points and SUI token rewards for platform activity and fee payment.
Pros
- Disclosed, precise fee and revenue figures
- Blue Points and SUI token rewards program for activity and fees paid
Cons
- Dynamic funding rates on perpetuals add variable cost beyond stated fees
Real, genuinely distinctive zkLogin onboarding and gasless trading. Real, Wormhole cross-chain bridging. Real, sophisticated security operations (Guardrail monitoring, Chaos Labs risk engine) that also function as genuine user-facing extras worth noting.
Pros
- Distinctive zkLogin onboarding; Wormhole bridging; sophisticated risk monitoring
Cons
- None significant found in our research
Access only through Bluefin's official app, and confirm you're not accessing it from a restricted jurisdiction.
Given the platform's architectural similarity to Cetus Protocol's concentrated-liquidity design, treat any large single position with the same caution you'd apply to any concentrated-liquidity AMM, and keep an eye on official security advisories.
A genuinely well-secured platform, honestly shrinking in the shadow of a neighbor's hack.
Bluefin earns real credit for taking security seriously in a way we can actually verify: six named audit firms, real-time monitoring, a disclosed risk engine, and credible, disclosed institutional backing are all genuine, substantive positives, and we found no confirmed hack of Bluefin itself. We also think it's important to be direct about two things most sources didn't dwell on. First, the platform's own most current, directly-sourced TVL figure is down sharply both month-over-month and relative to its own reported history from just over a year ago, a real, honest signal worth taking seriously rather than glossing over with an older, more flattering number. Second, when a neighboring, architecturally similar Sui DEX suffered one of the largest hacks we've documented anywhere in this project, independent researchers thought Bluefin's own design was similar enough to warrant a dedicated look. That's not the same as Bluefin having been hacked, and we want to be precise about that distinction, but it's also not nothing, and we think a fair review says so plainly.
The scorecard above is deliberately general. Whether Bluefin is right for you depends heavily on which of these you already are.
The Sui-native trader who wants extensively audited infrastructure and a genuinely modern, frictionless onboarding flow
This is genuinely where Bluefin's real strengths concentrate most heavily.
The trader specifically interested in Bluefin's disclosed, credible institutional backing and market-making support
Named backers and market makers are a real, verifiable trust signal worth weighing directly.
The user who follows Bluefin's official security advisories given its architectural similarity to a hacked neighbor
Given the real, adjacent concern researchers raised, this awareness is a genuinely reasonable step here specifically.
US residents, or traders prioritizing the deepest, most stable liquidity above the platform's other strengths
The disclosed geofencing and the honest recent TVL decline make this a real, honest consideration.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the Cetus-adjacent security analysis explained precisely, TVL's trajectory presented transparently, the audit and security-operations roster, and Bluefin against the full field, closing out this batch of reviews.
The Cetus-adjacent security analysis, precisely
| Detail | |
|---|---|
| What happened to Cetus | Cetus Protocol, a different Sui-based DEX, was hacked for $223 million on May 22, 2025 |
| Why Bluefin was examined | Bluefin Spot uses a similarly-designed concentrated-liquidity architecture |
| What the analysis found | No confirmed vulnerability in Bluefin; a cautionary examination given the architectural similarity |
| Was Bluefin hacked? | No; we found no disclosed exploit specific to Bluefin itself |
We're presenting this distinction carefully: an independent researcher raising a caution based on architectural similarity is real and worth knowing, but it is not the same as a confirmed exploit, and we don't want to blur that line either direction.
TVL, presented transparently
| Source | Figure cited |
|---|---|
| DefiLlama (current) | $20.25 million, down 20.1% over the past 30 days |
| Backpack Exchange learn article | "$84M+" |
| Gate Learn (Jan 2025 reference date) | $109.9 million |
We're weighting DefiLlama's current, directly-sourced, dated figure most heavily; the honest takeaway is a real, notable decline over time rather than a stable, sustained figure.
Audits and security operations
| Layer | Detail |
|---|---|
| Named audit firms | Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, OtterSec (six total) |
| Real-time monitoring | Guardrail threat monitoring system |
| Risk engine | Designed and monitored with Chaos Labs |
| Bug bounty | Active program via HackenProof |
| Disclosed trust assumption | Sequencer treated as a trusted party; explicitly out of bug-bounty scope |
This is a genuinely layered, multi-part security approach, among the most comprehensive we've documented in this series, with one honestly disclosed centralization exception in the sequencer.
Bluefin against the full field
| Bluefin | Orca | Hyperliquid | |
|---|---|---|---|
| Chain | Sui (primary) | Solana | Own L1 |
| Named audit firms | Six | Four | Three |
| Confirmed security incidents | None found | None found | None (JELLY was governance) |
| Distinctive feature | zkLogin onboarding; multi-layer security ops | Ocean-conservation fee allocation | Dominant liquidity |
Bluefin's disclosed-incident record sits alongside the cleanest platforms we've reviewed in this entire series, even accounting for the real, adjacent Cetus-related caution we've detailed above.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. We've excluded Bluefin's own official site and one specialized, security-focused technical analysis (not a general review) from this comparison.
Our score lands modestly below the aggregated industry average; most general sources describe Bluefin's security investment and backing favorably without directly grappling with the recent TVL decline or the Cetus-adjacent architectural caution the way our methodology does.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
No confirmed hack or exploit specific to Bluefin itself was found in our research. Following the May 2025 hack of a different, architecturally similar Sui DEX (Cetus Protocol), independent researchers examined Bluefin's design as a precaution, but did not confirm an actual vulnerability or breach.
Cetus Protocol, a separate, unrelated DEX on Sui, was hacked for $223 million on May 22, 2025. Because Bluefin Spot uses a similar concentrated-liquidity architecture, independent security researchers examined Bluefin specifically to see if similar risks might apply, as a cautionary exercise rather than in response to any actual incident at Bluefin.
Primarily Sui, since 2023. It technically also operates on Arbitrum, but per DefiLlama, Sui accounts for effectively 100% of current activity.
DefiLlama's current, directly-sourced figure is $20.25 million, down 20.1% over the past 30 days and dramatically smaller than an older, January 2025 figure of $109.9 million cited elsewhere.
Disclosed institutional backers include Polychain, SIG, Brevan Howard, and Tower Research, with liquidity support from market makers including Wintermute, Amber, and Keyrock.
No, Bluefin explicitly discloses that it's not available to United States residents.
A Sui-native feature letting users log in with a familiar account, like Google, in one click, rather than manually managing a separate crypto wallet from the start, genuinely reducing onboarding friction.
Six named firms: Trail of Bits, Halborn, Quantstamp, PeckShield, Hacken, and OtterSec, among the most extensively audited platforms we've reviewed in this series.
More Reviews
Balancer – DEX Review
Score: 47/100. The most incidents in this series: four since 2021, including a $116-128M hack that hit twice-audited code.
Read MoreHyperliquid – DEX Review
Score: 73/100. Dominant perp DEX, but closed-source code and the JELLY delisting controversy are real, unresolved trust questions.
Read MoreTHORChain – DEX Review
Score: 46/100. Unmatched native cross-chain swaps, carrying 2021 hacks, a $200M 2025 crisis, and use as a laundering conduit.
Read MoreRaydium – DEX Review
Score: 68/100. Solana's liquidity leader, carrying two confirmed incidents and a real, wide gap in third-party security ratings.
Read More



