{"investigation":{"slug":"venus-core-pool","entity_name":"Venus Core Pool","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Venus Core Pool is the primary lending market of Venus Protocol, the largest decentralized money market on BNB Chain. The protocol has accumulated over $112 million in cumulative losses across at least five separate security incidents since 2021, including oracle manipulation, a phishing attack draining $27 million from the Core Pool itself in September 2025, and a donation-attack exploit in March 2026 that left $2.15 million in unrecoverable bad debt. A critical vulnerability flagged during a 2023 Code4rena security audit was dismissed by the development team and subsequently exploited twice.","sections":[{"content":"Venus Protocol is a decentralized money market and lending platform operating primarily on BNB Chain (formerly Binance Smart Chain). It was launched in 2020 by the development team behind Swipe Wallet, a Visa debit card platform led by CEO Joselito Lizarondo. The protocol is a fork of Compound and MakerDAO, offering collateralized borrowing and lending, as well as a synthetic stablecoin (VAI). The native governance token, XVS, was distributed without pre-mine or founder allocation, with control passed entirely to token holders via Venus Improvement Proposals (VIPs). The Venus Core Pool is the original, primary pool of the protocol and historically held the majority of its total value locked. As of early 2026, Venus reported approximately $1.4 to $1.86 billion in total value locked, making it a significant but diminished component of BNB Chain DeFi relative to its 2021 peak of over $7 billion.","heading":"Protocol Overview","sources":[{"url":"https://academy.binance.com/en/articles/what-is-venus-protocol","name":"academy.binance.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/venus","name":"defillama.com","type":"other","credibility":3},{"url":"https://coincentral.com/venus-protocol-guide/","name":"coincentral.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 2, 2025, Venus Protocol confirmed a security incident in which approximately $27 million was drained from the Core Pool. Blockchain security firm Cyvers Alerts first reported that the protocol's Core Pool Comptroller contract had been linked to a malicious address. The breach was ultimately attributed to a phishing attack: a large protocol user was tricked into approving a malicious transaction that granted unlimited token transfer permissions. Stolen assets included approximately $19.8 million in vUSDT, $7.15 million in vUSDC, and 285 BTCB. Venus suspended withdrawals and liquidations immediately following the incident. Within hours, the protocol initiated a 'lightning vote,' a community-driven emergency governance process that received 100% community support, enabling forced liquidation of the attacker's assets. The protocol reported recovering $13.5 million through this forced liquidation. Venus confirmed full restoration of services on September 3, 2025. The incident highlighted the exposure of the Core Pool to both social engineering attacks and governance-layer intervention as a recovery mechanism.","heading":"September 2025 Core Pool Exploit ($27 Million)","sources":[{"url":"https://www.coindesk.com/tech/2025/09/02/bnb-chain-based-venus-protocol-drained-of-usd27m-on-suspected-contract-compromise","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/09/03/venus-protocol-restores-services-recovers-stolen-funds-after-usd27m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://crypto-economy.com/venus-protocol-confirms-core-pool-exploit-27m-drained/","name":"crypto-economy.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/09/03/venus-protocol-fully-resumes-after-27m-phishing-exploit/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 15, 2026, an attacker executed a donation-style price manipulation attack on the vTHE market within Venus Protocol, targeting the THE token issued by Thena, a BNB Chain DeFi platform. The attack resulted in approximately $3.7 million extracted from the protocol and $2.15 million in unrecoverable bad debt, composed of roughly 1.18 million CAKE tokens and 1.84 million THE tokens. The attacker spent approximately nine months accumulating approximately 84% of Venus's THE token supply cap, with the initial funding of approximately 7,400 ETH withdrawn from the Tornado Cash mixing protocol. Rather than depositing via the standard mint() function — which would enforce supply caps — the attacker transferred tokens directly to the vTHE smart contract (a 'donation'), artificially inflating the contract's internal exchange rate by approximately 3.81 times. This massively increased borrowing power, allowing the attacker to borrow roughly $14.9 million in BTCB, CAKE, USDC, and other assets. THE's price was pushed from approximately $0.26 to nearly $4 through recursive DEX purchases before collapsing. The attacker ultimately suffered a net loss of approximately $4.7 million due to the price collapse. The Core Pool was left with $2.15 million in bad debt following 8,048 cascading liquidations. Critically, this exact vulnerability class had been documented by Code4rena auditors in May 2023 under finding M-10 of the Venus Isolated Pools audit. The Venus development team dismissed the finding, describing direct token donations as 'supported behavior with no negative side effects.' An earlier, nearly identical attack exploiting the same mechanism on Venus's ZKSync deployment in February 2025 had already resulted in approximately $717,000 in bad debt. The BNB Chain Core Pool shared the same unpatched vulnerability. Venus responded to the March 2026 exploit by pausing THE borrows and withdrawals, setting THE's collateral factor to zero, and reducing collateral factors to zero on six additional markets: Bitcoin Cash (BCH), Litecoin (LTC), Uniswap (UNI), Aave (AAVE), Filecoin (FIL), and Trust Wallet Token (TWT).","heading":"March 2026 Donation Attack — Dismissed Audit Finding Exploited","sources":[{"url":"https://rekt.news/venus-protocol-rekt4","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/393622/venus-protocol-left-with-roughly-2m-in-bad-debt-after-exploit-manipulates-thenas-the-token-price","name":"theblock.co","type":"other","credibility":3},{"url":"https://dev.to/ohmygod/the-venus-protocol-donation-attack-how-a-dismissed-audit-finding-became-a-215m-bad-debt-twice-4lk9","name":"dev.to","type":"other","credibility":3},{"url":"https://code4rena.com/reports/2023-05-venus","name":"code4rena.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2026/03/19/venus-xvs-token-plunges-9-as-exploit-leaves-protocol-with-bad-debt","name":"coindesk.com","type":"other","credibility":3},{"url":"https://protos.com/venus-protocol-hacker-lost-4-7m-after-nine-months-of-planning/","name":"protos.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In May 2021, Venus Protocol's Core Pool incurred over $95 million in bad debt following an oracle manipulation attack targeting its own governance token, XVS. An attacker exploited the relatively thin liquidity of XVS on centralized exchanges to push its price from approximately $70 to over $140 in a short period. Using XVS as collateral at the inflated price, borrowers withdrew approximately 2,000 BTC and 5,700 ETH from the protocol. When XVS prices corrected, the collateral was insufficient to cover outstanding loans. Market liquidity could not absorb forced liquidation sell-offs at scale, leaving the protocol with $95 million in uncollateralized exposure. The bad debt was reportedly addressed over subsequent years through protocol revenue.","heading":"2021 XVS Oracle Manipulation — $95 Million Bad Debt","sources":[{"url":"https://quillhashteam.medium.com/200-m-venus-protocol-hack-analysis-b044af76a1ae","name":"quillhashteam.medium.com","type":"other","credibility":3},{"url":"https://thedefiant.io/bscs-venus-protocol-left-with-bad-debt-after-liquidations","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://www.chaincatcher.com/en/article/2252203","name":"chaincatcher.com","type":"other","credibility":3}],"severity":"medium"},{"content":"During the collapse of the Terra/LUNA ecosystem in May 2022, Venus Protocol absorbed approximately $14 million in bad debt. LUNA had been enabled as a collateral asset on Venus and relied on Chainlink price feeds. The LUNA price feed contract contained a hard-coded minimum value of approximately $0.10 and a circuit breaker that paused price updates at the minimum threshold. As LUNA's market price fell well below $0.10 (to approximately $0.01), Venus continued processing transactions at the stale minimum price. Before the team could pause the protocol, users exploited the discrepancy, creating approximately $14–15 million in undercollateralized positions.","heading":"2022 Terra/LUNA Collapse — $14 Million Bad Debt","sources":[{"url":"https://www.chaincatcher.com/en/article/2252203","name":"chaincatcher.com","type":"other","credibility":3},{"url":"https://messari.io/report/venus-money-market-and-synthetic-stablecoin-protocol-on-bnb-chain","name":"messari.io","type":"other","credibility":3}],"severity":"medium"},{"content":"In October 2022, the attacker behind the BNB Chain cross-chain bridge exploit (which generated approximately $566 million in unauthorized BNB) deposited approximately 900,000 BNB as collateral on Venus Protocol to borrow $150 million in stablecoins, including USDT, USDC, and BUSD. Concerns arose that forced liquidation of this position could dump hundreds of millions of dollars in BNB onto the open market, potentially destabilizing BNB's price. BNB Chain passed a governance proposal granting the core team authority to liquidate the position in a controlled manner if it approached the liquidation threshold. The position was ultimately handled via a whitelisted liquidation without resulting shortfall or further protocol impact. Venus Protocol subsequently liquidated approximately $30 million linked to this account in a separate action.","heading":"2022 BNB Chain Bridge Hack — Stolen Funds Used as Collateral","sources":[{"url":"https://www.theblock.co/post/246291/venus-protocol-bnb","name":"theblock.co","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/binance-bridge-hacker-hit-by-usd30m-liquidation-on-venus","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/bnb-chain-team-prepares-to-step-in-to-prevent-massive-venus-protocol-liquidation","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Venus Protocol's governance structure has drawn attention following multiple security incidents. The protocol relies on XVS token holders to vote on Venus Improvement Proposals (VIPs), including emergency measures. In September 2025, the governance system demonstrated rapid response capability via a 'lightning vote' that enabled forced liquidation of a $27 million attacker position. However, critics have noted that the same governance structure allowed the 2021 XVS manipulation attack to cause outsized damage by permitting XVS to serve as collateral for the protocol's own money market. Community members also alleged they raised concerns about the attacker's accumulation of THE tokens prior to the March 2026 exploit, but the protocol did not act. The development team's decision to dismiss the Code4rena audit finding and its failure to apply cross-deployment patches following the February 2025 ZKSync exploit raise questions about the adequacy of its security governance processes.","heading":"Governance and Decentralization Concerns","sources":[{"url":"https://dev.to/ohmygod/the-venus-protocol-donation-attack-how-a-dismissed-audit-finding-became-a-215m-bad-debt-twice-4lk9","name":"dev.to","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/09/03/venus-protocol-restores-services-recovers-stolen-funds-after-usd27m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://rekt.news/venus-protocol-rekt4","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Venus Protocol has accumulated over $112 million in cumulative losses across at least five separate incidents since 2021, making it one of the most repeatedly exploited lending protocols in DeFi history. The incidents span oracle manipulation, stale price feeds, phishing-induced access compromise, and donation attacks — a diverse range of attack vectors suggesting persistent inadequacy in security processes rather than a single correctable vulnerability. The March 2026 incident is particularly notable because the same vulnerability had been: (1) formally identified by third-party auditors in 2023, (2) dismissed by the development team, (3) exploited on a secondary deployment in 2025, and (4) left unpatched on the primary BNB Chain deployment before the 2026 attack. The Protos reporting noted the attacker in the March 2026 incident lost more than they extracted, but the protocol bore the full cost of the residual bad debt. The ChainCatcher analysis described Venus as having been 'reduced to a hacker's ATM' given its repeated compromise history.","heading":"Cumulative Risk Profile","sources":[{"url":"https://www.chaincatcher.com/en/article/2252203","name":"chaincatcher.com","type":"other","credibility":3},{"url":"https://protos.com/venus-protocol-hacker-lost-4-7m-after-nine-months-of-planning/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=venus-protocol-bad-debt","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2026/03/19/donation-attack-on-venus-protocol-leaves-2-15-million-in-bad-debt/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020","event":"Venus Protocol launched on BNB Chain by the Swipe Wallet development team, forking Compound and MakerDAO","source":"","date_original":"2020-01-01"},{"date":"2021-05","event":"XVS oracle manipulation attack; attacker pumps XVS price from ~$70 to ~$140, borrows ~2,000 BTC and ~5,700 ETH; protocol left with $95 million in bad debt","source":"","date_original":"2021-05-01"},{"date":"2022-05","event":"Terra/LUNA collapse causes $14 million in bad debt on Venus due to stale Chainlink price feed with hard-coded $0.10 minimum for LUNA","source":"","date_original":"2022-05-01"},{"date":"2022-10","event":"BNB Chain bridge exploiter deposits 900,000 BNB as collateral on Venus to borrow $150 million in stablecoins; BNB Chain governance intervenes to prevent destabilizing liquidation","source":"","date_original":"2022-10-01"},{"date":"2023-05","event":"Code4rena audit of Venus Isolated Pools documents donation attack vector under finding M-10; Venus development team dismisses it as 'supported behavior with no negative side effects'","source":"","date_original":"2023-05-01"},{"date":"2025-02","event":"Venus ZKSync deployment suffers donation-style exploit on wUSDM market; approximately $717,000 in net bad debt incurred; BNB Chain deployment left unpatched","source":"","date_original":"2025-02-01"},{"date":"2025-06","event":"Alleged attacker begins nine-month accumulation of THE (Thena) tokens on Venus, funded via ~7,400 ETH from Tornado Cash; community members allegedly raise concerns; Venus declines to act","source":"","date_original":"2025-06-01"},{"date":"2025-09-02","event":"Core Pool exploit: phishing attack tricks large protocol user into approving malicious transaction; approximately $27 million in vUSDT, vUSDC, and BTCB drained from Venus Core Pool","source":""},{"date":"2025-09-03","event":"Venus 'lightning vote' passes with 100% community support; forced liquidation of attacker assets recovers approximately $13.5 million; protocol fully restores services","source":""},{"date":"2026-03-15","event":"Donation attack on vTHE market: attacker donates 36+ million THE directly to vTHE contract, inflates exchange rate 3.81x, borrows ~$14.9 million in assets; THE price collapses; $2.15 million in bad debt remains","source":""},{"date":"2026-03-19","event":"XVS governance token falls approximately 9% following disclosure of bad debt; Venus pauses THE market and reduces collateral factors to zero on six additional markets","source":""}],"sources_used":[{"url":"https://academy.binance.com/en/articles/what-is-venus-protocol","name":"academy.binance.com","type":"other","archive_url":"http://web.archive.org/web/20250909073338/https://academy.binance.com/en/articles/what-is-venus-protocol","credibility":3,"archive_timestamp":"2025-09-09T07:33:38+00:00"},{"url":"https://defillama.com/protocol/venus","name":"defillama.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coincentral.com/venus-protocol-guide/","name":"coincentral.com","type":"other","archive_url":"https://web.archive.org/web/20260829025632/https://coincentral.com/blockfi-vs-crypto-com/","credibility":3,"archive_timestamp":"2026-08-29T02:56:32+00:00"},{"url":"https://www.coindesk.com/tech/2025/09/02/bnb-chain-based-venus-protocol-drained-of-usd27m-on-suspected-contract-compromise","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260322053838/https://www.coindesk.com/tech/2025/09/02/bnb-chain-based-venus-protocol-drained-of-usd27m-on-suspected-contract-compromise","credibility":3,"archive_timestamp":"2026-03-22T05:38:38+00:00"},{"url":"https://www.coindesk.com/business/2025/09/03/venus-protocol-restores-services-recovers-stolen-funds-after-usd27m-exploit","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20250917205251/https://www.coindesk.com/business/2025/09/03/venus-protocol-restores-services-recovers-stolen-funds-after-usd27m-exploit","credibility":3,"archive_timestamp":"2025-09-17T20:52:51+00:00"},{"url":"https://crypto-economy.com/venus-protocol-confirms-core-pool-exploit-27m-drained/","name":"crypto-economy.com","type":"other","archive_url":"http://web.archive.org/web/20251015083213/https://crypto-economy.com/venus-protocol-confirms-core-pool-exploit-27m-drained/","credibility":3,"archive_timestamp":"2025-10-15T08:32:13+00:00"},{"url":"https://www.cryptotimes.io/2025/09/03/venus-protocol-fully-resumes-after-27m-phishing-exploit/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20250906201544/https://www.cryptotimes.io/2025/09/03/venus-protocol-fully-resumes-after-27m-phishing-exploit/","credibility":3,"archive_timestamp":"2025-09-06T20:15:44+00:00"},{"url":"https://rekt.news/venus-protocol-rekt4","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260513155858/https://rekt.news/venus-protocol-rekt4","credibility":3,"archive_timestamp":"2026-05-13T15:58:58+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260528032633/https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026","credibility":3,"archive_timestamp":"2026-05-28T03:26:33+00:00"},{"url":"https://www.theblock.co/post/393622/venus-protocol-left-with-roughly-2m-in-bad-debt-after-exploit-manipulates-thenas-the-token-price","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260731061222/https://www.theblock.co/post/393622/venus-protocol-left-with-roughly-2m-in-bad-debt-after-exploit-manipulates-thenas-the-token-price","credibility":3,"archive_timestamp":"2026-07-31T06:12:22+00:00"},{"url":"https://dev.to/ohmygod/the-venus-protocol-donation-attack-how-a-dismissed-audit-finding-became-a-215m-bad-debt-twice-4lk9","name":"dev.to","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://code4rena.com/reports/2023-05-venus","name":"code4rena.com","type":"other","archive_url":"http://web.archive.org/web/20260309064334/https://code4rena.com/reports/2023-05-venus","credibility":3,"archive_timestamp":"2026-03-09T06:43:34+00:00"},{"url":"https://www.coindesk.com/markets/2026/03/19/venus-xvs-token-plunges-9-as-exploit-leaves-protocol-with-bad-debt","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260726092952/https://www.coindesk.com/markets/2026/03/19/venus-xvs-token-plunges-9-as-exploit-leaves-protocol-with-bad-debt","credibility":3,"archive_timestamp":"2026-07-26T09:29:52+00:00"},{"url":"https://protos.com/venus-protocol-hacker-lost-4-7m-after-nine-months-of-planning/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260416013225/https://protos.com/venus-protocol-hacker-lost-4-7m-after-nine-months-of-planning/","credibility":3,"archive_timestamp":"2026-04-16T01:32:25+00:00"},{"url":"https://quillhashteam.medium.com/200-m-venus-protocol-hack-analysis-b044af76a1ae","name":"quillhashteam.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260705205210/https://quillhashteam.medium.com/200-m-venus-protocol-hack-analysis-b044af76a1ae","credibility":3,"archive_timestamp":"2026-07-05T20:52:10+00:00"},{"url":"https://thedefiant.io/bscs-venus-protocol-left-with-bad-debt-after-liquidations","name":"thedefiant.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.chaincatcher.com/en/article/2252203","name":"chaincatcher.com","type":"other","archive_url":"http://web.archive.org/web/20260412232811/https://www.chaincatcher.com/en/article/2252203","credibility":3,"archive_timestamp":"2026-04-12T23:28:11+00:00"},{"url":"https://messari.io/report/venus-money-market-and-synthetic-stablecoin-protocol-on-bnb-chain","name":"messari.io","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.theblock.co/post/246291/venus-protocol-bnb","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://thedefiant.io/news/defi/binance-bridge-hacker-hit-by-usd30m-liquidation-on-venus","name":"thedefiant.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.web3isgoinggreat.com/single/bnb-chain-team-prepares-to-step-in-to-prevent-massive-venus-protocol-liquidation","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260816110203/https://www.web3isgoinggreat.com/single/bnb-chain-team-prepares-to-step-in-to-prevent-massive-venus-protocol-liquidation","credibility":3,"archive_timestamp":"2026-08-16T11:02:03+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=venus-protocol-bad-debt","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260703184854/https://www.web3isgoinggreat.com/?id=venus-protocol-bad-debt","credibility":3,"archive_timestamp":"2026-07-03T18:48:54+00:00"},{"url":"https://www.cryptotimes.io/2026/03/19/donation-attack-on-venus-protocol-leaves-2-15-million-in-bad-debt/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20260725004013/https://www.cryptotimes.io/2026/03/19/donation-attack-on-venus-protocol-leaves-2-15-million-in-bad-debt/","credibility":3,"archive_timestamp":"2026-07-25T00:40:13+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:24.912952+00:00","updated_at":"2026-08-29T18:16:46.89419+00:00"}}