Sui Validator Security Benchmark — September 2025
Abstract
This article summarizes NullRabbit’s September 2025 validator security dataset for the Sui ecosystem. The benchmark provides a transparent baseline of validator posture using a consolidated scoring model; it intentionally excludes vulnerability specifics (e.g., CVE lists) to avoid sensitive disclosures while still enabling comparison and improvement over time.
Methodology
- Publicly reachable validator endpoints were scanned using NullRabbit’s framework.
- Each validator received a 0–100 composite score derived from non-sensitive indicators of security posture and reliability.
- Data collected: 122 validators; 119 with valid scores.
Key Findings (September 2025)
- Score distribution ranged from 15 to 93.
- Median score: 45.
- 18.5% of validators met or exceeded the recommended “good practice” threshold of 70.
Data Outputs
- Interactive Heatmap: https://nullrabbit.ai/heatmaps/2025-09-sui
- Research Repo: https://github.com/nullrabbitlabs/nullrabbit-research/blob/main/reports/2025-09-sui.md
Validator Tools
Validators can query and rescan their scores through the NullRabbit Sentinel Discord Bot, and claim ownership for enhanced analytics.
Privacy & Safety
To promote responsible disclosure, NullRabbit publishes consolidated scores only in public datasets. Detailed findings, where applicable, are communicated privately with operators upon verification of ownership.
Conclusion
This benchmark is intended as a positive ecosystem health check. By publishing consolidated scores openly, NullRabbit supports validator communities in raising standards and strengthening decentralized networks. Monthly updates will provide ongoing visibility into improvements and trends.
Full Article
You can read the full article on our blog here
NullRabbit.ai conducts independent research into decentralized infrastructure security. Our mission: expose systemic risks before they cascade into systemic failures.
Related Posts
Sui Validators: A Billion-Dollar Liability
NullRabbit.ai’s scan of the Sui validator set found nearly 40% of voting power exposed. Misconfigurations, open ports, and unpatched CVEs turn Sui’s ‘critical infrastructure’ into a billion-dollar liability.
Validator Slashing Incidents Are a Warning. Sui Could Be Next.
Recent Ethereum validator slashings showed how fragile infra can be. Our scan of Sui uncovered something worse: nearly 40% of validator voting power exposed.
Sui Validator Network Exposed: Nearly 40% at Risk
NullRabbit's August 2025 scan of the Sui validator set revealed nearly 40% of voting power exposed to SSH, CVEs, and misconfigurations — leaving the network one step away from consensus failure.