{"investigation":{"slug":"venus-protocol-the-token-flash-loan-exploit-march-2026","entity_name":"Venus Protocol THE Token Flash-Loan Exploit (March 2026)","trust_score":5,"severity_base":null,"score_modifier":-7,"confidence":0.89,"status":"published","content_type":"investigation","summary":"On March 15, 2026, Venus Protocol's BNB Chain Core Pool was exploited via a donation-attack supply-cap bypass targeting the THENA (THE) token market, resulting in approximately $3.7 to $5.07 million in extracted assets and $2.15 million in residual bad debt. The attacker conducted a nine-month preparation phase funded by 7,447 ETH received through Tornado Cash, and exploited a getCashPrior() vulnerability in Venus's Compound-forked vToken contracts that had been documented in a May 2023 Code4rena audit and previously exploited on Venus's zkSync deployment in February 2025, yet was not patched across all protocol deployments prior to this larger incident.","sections":[{"content":"Venus Protocol is a decentralized algorithmic money market on BNB Chain, described at the time of the exploit as the chain's largest lending platform with approximately $1.47 billion in total value locked. This investigation concerns specifically the exploit of the THE (THENA) token market within Venus Protocol's BNB Chain Core Pool on March 15, 2026. Early media reports characterized the incident as a 'flash loan attack,' but on-chain forensics from BlockSec and the protocol's own post-mortem classify it as a donation attack combined with price manipulation and illiquid collateral concentration. The attacker did not use a single-block flash loan; instead, the attack relied on a nine-month token accumulation campaign, a direct vToken contract balance donation to bypass supply caps, and a recursive borrow loop. Venus Protocol acknowledged the incident publicly on the day of the exploit and published a formal community post-mortem on approximately March 17, 2026.","heading":"Incident Overview and Classification","sources":[{"url":"https://community.venus.io/t/the-market-incident-post-mortem/5712","name":"THE Market Incident Post-Mortem — Venus Community Forum","type":"official","credibility":1},{"url":"https://blocksec.com/blog/venus-thena-donation-attack","name":"Venus Thena (THE) Incident: What Broke and What Was Missed — BlockSec Blog","type":"research","credibility":2},{"url":"https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026","name":"Explained: The Venus Protocol Hack (March 2026) — Halborn Security","type":"research","credibility":2},{"url":"https://www.theblock.co/post/393622/venus-protocol-left-with-roughly-2m-in-bad-debt-after-exploit-manipulates-thenas-the-token-price","name":"Venus Protocol left with roughly $2M in bad debt — The Block","type":"news_article","credibility":1}],"severity":"critical"},{"content":"On-chain forensics published by BlockSec and referenced in Venus Protocol's official post-mortem identify three addresses central to the attack. The primary collateral position was held by address 0x1A35bD28EFD46CfC46c2136f878777D69ae16231. The primary attacker EOA is identified as 0x43c743e316f40d4511762eedf6f6d484f67b2f82. The attack execution contract is 0x737bc98f1d34e19539c074b8ad1169d5d45da619. Beginning in June 2025, a funding wallet received approximately 7,447 ETH — valued at roughly $16.29 million — across 77 separate withdrawal transactions from Tornado Cash, the OFAC-sanctioned Ethereum mixing service. The funded wallet subsequently deposited the ETH into the Aave lending protocol as collateral to borrow approximately $9.92 million in stablecoins, which were routed through intermediary addresses and used over nine months to accumulate approximately 12.2 million THE tokens representing 84% of Venus's 14.5 million THE supply cap. The use of Tornado Cash for initial funding is consistent with deliberate obfuscation of attack capital. No real-world identity for the attacker has been publicly confirmed as of the investigation date.","heading":"Attacker Identity and Funding Chain","sources":[{"url":"https://blocksec.com/blog/venus-thena-donation-attack","name":"Venus Thena (THE) Incident: What Broke and What Was Missed — BlockSec Blog","type":"research","credibility":2},{"url":"https://community.venus.io/t/the-market-incident-post-mortem/5712","name":"THE Market Incident Post-Mortem — Venus Community Forum","type":"official","credibility":1},{"url":"https://blockchain.news/flashnews/venus-attacker-transfers-eth-tornado-cash","name":"Venus Attacker Transfers ETH to Tornado Cash — Blockchain.news","type":"on_chain","credibility":2},{"url":"https://rekt.news/venus-protocol-rekt4","name":"Venus Protocol - Rekt IV — Rekt News","type":"research","credibility":2}],"severity":"critical"},{"content":"The root vulnerability is a design flaw in Compound-forked vToken contracts. Venus's supply cap enforcement is applied exclusively within the mint() function, the standard deposit pathway that issues vTokens in exchange for underlying assets. The protocol's getCashPrior() function reads the vToken contract's raw ERC-20 token balance rather than an internally tracked supply state. Because direct ERC-20 transfers to the contract do not invoke mint(), an attacker may inflate the contract's balance — and therefore its exchange rate — without triggering supply cap checks. The attacker transferred approximately 36.1 million THE tokens directly to the vTHE contract address, causing the exchange rate to rise from 10,086,934,836 to 38,420,106,438, a 3.81x increase. This inflated exchange rate caused the protocol to value the attacker's existing 12.2 million vTHE position as if it were backed by 53.23 million THE, which is 367% of the 14.5 million supply cap. The attacker then executed a recursive borrow loop from approximately 12:00 to 12:42 UTC: borrowing assets against the inflated collateral, swapping borrowed assets into additional THE on the open market, donating the acquired THE back to the vTHE contract to further inflate the exchange rate, and repeating. At peak the attacker had borrowed approximately $14.9 million in assets.","heading":"Technical Mechanism: getCashPrior() Donation Attack and Supply Cap Bypass","sources":[{"url":"https://blocksec.com/blog/venus-thena-donation-attack","name":"Venus Thena (THE) Incident: What Broke and What Was Missed — BlockSec Blog","type":"research","credibility":2},{"url":"https://community.venus.io/t/the-market-incident-post-mortem/5712","name":"THE Market Incident Post-Mortem — Venus Community Forum","type":"official","credibility":1},{"url":"https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026","name":"Explained: The Venus Protocol Hack (March 2026) — Halborn Security","type":"research","credibility":2},{"url":"https://dev.to/ohmygod/the-venus-protocol-donation-attack-how-a-compound-forks-getcashprior-let-an-attacker-bypass-1ggc","name":"The Venus Protocol Donation Attack: getCashPrior() supply cap bypass — DEV Community","type":"research","credibility":2}],"severity":"critical"},{"content":"Concurrent with the donation bypass, the attacker's recursive purchases of THE tokens on thin on-chain markets created sustained upward price pressure. THE's spot price rose from approximately $0.26 pre-attack to a reported manipulation peak ranging from $0.51 (as accepted by Venus's oracle) to nearly $4.00 on the Binance price feed before the BoundValidator rejected those readings. According to Venus's community post-mortem, Venus's Resilient Oracle — which aggregates the RedStone and Binance feeds and applies a BoundValidator to reject anomalous price data — initially rejected the manipulated Binance feed data, reverting price reads for approximately 37 minutes. After that window, the oracle accepted a THE price of approximately $0.51, roughly twice the pre-attack market price. This accepted price was still far above what could be liquidated safely given THE's on-chain liquidity depth, contributing to the bad debt outcome. Once the attacker ceased buying and the position began to unwind, THE collapsed to approximately $0.22, below the pre-attack price. The oracle's BoundValidator upper bounds for THE were subsequently identified as set too loosely relative to realistic market depth for an illiquid asset.","heading":"Price Manipulation and Oracle Behavior","sources":[{"url":"https://community.venus.io/t/the-market-incident-post-mortem/5712","name":"THE Market Incident Post-Mortem — Venus Community Forum","type":"official","credibility":1},{"url":"https://www.ainvest.com/news/venus-protocol-exploit-flow-3-7m-illiquid-collateral-risk-2603/","name":"Venus Protocol Exploit: Flow of $3.7M and the Illiquid Collateral Risk — Ainvest","type":"research","credibility":2},{"url":"https://en.cryptonomist.ch/2026/03/16/venus-protocol-hack-bnb/","name":"Venus Protocol hack triggers $3.7 million loss — Cryptonomist","type":"news_article","credibility":2}],"severity":"high"},{"content":"The attacker borrowed and extracted the following assets during the recursive loop phase: approximately 6,669,112 CAKE tokens, 2,801 BNB, 1,972 WBNB, 1,581,461 USDC, and 20 BTCB (tokenized bitcoin). The total gross extraction is estimated at $3.7 million to $5.07 million depending on the accounting method used across different analyst reports. After the exploit, 8,048 liquidation transactions executed by 254 unique liquidation bot addresses unwound approximately 42 million THE in collateral at post-collapse prices. Venus Protocol was left with approximately $2.15 million in unrecoverable bad debt, consisting primarily of approximately 1.184 million CAKE tokens and 1.919 million THE tokens, plus smaller amounts of DAI, BNB, and ETH. The Venus community governance proposal placed the total bad-debt figure at $2,203,024 across 19 affected assets. On-chain analysis by BlockSec and Protos indicates the exploit was unprofitable for the attacker when investment costs are included: the attacker invested approximately $9.92 million in borrowed stablecoin capital and retained approximately $5.21 million in extracted assets, for an estimated net on-chain loss of approximately $4.71 million. Some analysts have noted the attacker may have hedged the position via short contracts on centralized exchanges, but no direct evidence of off-chain profit has been confirmed.","heading":"Financial Impact: Extracted Assets and Bad Debt","sources":[{"url":"https://blocksec.com/blog/venus-thena-donation-attack","name":"Venus Thena (THE) Incident: What Broke and What Was Missed — BlockSec Blog","type":"research","credibility":2},{"url":"https://community.venus.io/t/bnb-chain-the-market-bad-debt-repayment/5719","name":"BNB Chain THE Market Bad Debt Repayment — Venus Community Forum","type":"official","credibility":1},{"url":"https://protos.com/venus-protocol-hacker-lost-4-7m-after-nine-months-of-planning/","name":"Venus Protocol hacker lost $4.7M after nine months of planning — Protos","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/markets/2026/03/19/venus-xvs-token-plunges-9-as-exploit-leaves-protocol-with-bad-debt","name":"Venus' governance token XVS plunges 9% over exploit-driven bad debt — CoinDesk","type":"news_article","credibility":1}],"severity":"high"},{"content":"The donation-attack vector used in the March 2026 exploit was communicated to Venus Protocol on at least two prior occasions before this incident. First, during Venus Protocol's May 2023 Code4rena Isolated Pools security audit, finding M-10 documented how direct ERC-20 transfers to a vToken contract could bypass supply cap enforcement. The finding included a working proof of concept. Venus Protocol's security team disputed and dismissed the finding, stating that donations were 'an intentional feature with no negative side effects.' Second, in February 2025, a substantially identical donation attack was executed against Venus Protocol's zkSync deployment, targeting the wUSDM market via a direct ERC-4626 donation. That incident resulted in approximately $716,789 in net bad debt for the protocol. Despite this confirmed exploitation of the exact same mechanism, the vulnerability was not patched universally across Venus's BNB Chain Core Pool deployment prior to the March 2026 incident. Venus Protocol's post-March 2026 remediation acknowledges the codebase gap and commits to closing it across all deployments, confirming the root cause had persisted unaddressed through both incidents.","heading":"Prior Warnings: Dismissed Audit Finding and Precursor Exploit","sources":[{"url":"https://code4rena.com/reports/2023-05-venus","name":"Venus Protocol Isolated Pools Findings & Analysis Report — Code4rena","type":"research","credibility":1},{"url":"https://code4rena.com/audits/2023-05-venus-protocol-isolated-pools","name":"Venus Protocol Isolated Pools Audit — Code4rena","type":"research","credibility":1},{"url":"https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026","name":"Explained: The Venus Protocol Hack (March 2026) — Halborn Security","type":"research","credibility":2},{"url":"https://rekt.news/venus-protocol-rekt4","name":"Venus Protocol - Rekt IV — Rekt News","type":"research","credibility":2},{"url":"https://dev.to/ohmygod/the-venus-protocol-donation-attack-how-a-dismissed-audit-finding-became-a-215m-bad-debt-twice-4lk9","name":"Donation Attack: How a Dismissed Audit Finding Became a $2.15M Bad Debt — Twice — DEV Community","type":"research","credibility":2}],"severity":"critical"},{"content":"Venus Protocol's risk team implemented emergency containment measures on March 15, 2026: borrowing and withdrawals in the THE market were paused; THE's collateral factor was set to zero; and six additional markets with concentrated collateral positions (BCH, LTC, UNI, AAVE, FIL, TWT) were frozen as a precaution. Other markets remained operational. An emergency governance proposal to freeze approximately $3 million in assets still controlled by the attacker was passed, contributing to the attacker's estimated net on-chain loss. Allez Labs, Venus Protocol's designated risk manager, initiated a post-incident review of oracle protections and supply cap enforcement parameters. The official post-mortem was published on approximately March 17, 2026. A separate governance proposal was subsequently submitted to fully repay $2,203,024 in bad debt via the Venus Treasury and Risk Fund. The BoundValidator price parameters for illiquid collateral assets were identified for tightening. A code-level fix replacing getCashPrior()'s direct balance read with an internalCash state variable was committed to close the donation bypass going forward. As of the investigation date, the bad-debt governance vote outcome was pending community approval.","heading":"Protocol Response and Governance Actions","sources":[{"url":"https://community.venus.io/t/the-market-incident-post-mortem/5712","name":"THE Market Incident Post-Mortem — Venus Community Forum","type":"official","credibility":1},{"url":"https://community.venus.io/t/bnb-chain-the-market-bad-debt-repayment/5719","name":"BNB Chain THE Market Bad Debt Repayment — Venus Community Forum","type":"official","credibility":1},{"url":"https://beincrypto.com/venus-protocol-exploit-the-token-collateral/","name":"Venus Freezes 6 Collateral Markets, Thena Finally Speaks Out — BeInCrypto","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/markets/2026/03/19/venus-xvs-token-plunges-9-as-exploit-leaves-protocol-with-bad-debt","name":"Venus' governance token XVS plunges 9% over exploit-driven bad debt — CoinDesk","type":"news_article","credibility":1}],"severity":"medium"},{"content":"The March 2026 incident is the fourth publicly documented major exploit affecting Venus Protocol since its 2020 launch, labeled 'Rekt IV' by Rekt News. In May 2021, an attacker manipulated the XVS governance token price on Binance from approximately $70 to over $140, then used inflated XVS as collateral to borrow approximately 2,000 BTC and 5,700 ETH, resulting in approximately $95 million in bad debt. In May 2022, Venus absorbed approximately $14 million in bad debt from the Terra/LUNA collapse after a Chainlink oracle paused price updates, allowing borrowers to continue drawing against LUNA collateral at erroneous prices. In October 2022, the BNB Bridge exploiter borrowed large quantities of stablecoins against stolen BNB and remains a top-16 XVS holder with approximately 135,000 XVS. In September 2025, a $27 million phishing attack targeted a large individual Venus user, of which approximately $13 million was reportedly recovered; this incident was attributed to a compromised individual rather than a protocol-level vulnerability. In February 2025, the donation attack vector was first exploited live against Venus's zkSync deployment. Security researchers estimate Venus Protocol's cumulative losses across all incidents at over $112 million. Additionally, CoinDesk reported that Justin Sun-linked wallets moved 621,071 XVS ($1.95 million) to HTX exchange on March 16, 2026, one day after the exploit. CoinDesk noted that no direct connection to the exploit has been established.","heading":"Venus Protocol Exploit History and Cumulative Losses","sources":[{"url":"https://rekt.news/venus-protocol-rekt4","name":"Venus Protocol - Rekt IV — Rekt News","type":"research","credibility":2},{"url":"https://quillhashteam.medium.com/200-m-venus-protocol-hack-analysis-b044af76a1ae","name":"$200M Venus Protocol hack analysis — QuillAudits / Medium","type":"research","credibility":2},{"url":"https://protos.com/fears-of-27m-venus-protocol-hack-turn-out-to-be-phishing-attack-on-power-user/","name":"Fears of $27M Venus Protocol hack turn out to be phishing attack — Protos","type":"news_article","credibility":2},{"url":"https://www.cryptotimes.io/2026/03/19/donation-attack-on-venus-protocol-leaves-2-15-million-in-bad-debt/","name":"Donation Attack on Venus Protocol Leaves $2.15 Million in Bad Debt — Crypto Times","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/markets/2026/03/19/venus-xvs-token-plunges-9-as-exploit-leaves-protocol-with-bad-debt","name":"Venus' governance token XVS plunges 9% over exploit-driven bad debt — CoinDesk","type":"news_article","credibility":1}],"severity":"high"}],"timeline":[{"date":"2023-05","event":"Code4rena audit of Venus Protocol Isolated Pools documents the donation-attack supply cap bypass as finding M-10, including a working proof of concept. Venus Protocol team dismisses the finding, stating donations are 'supported behavior with no negative side effects.'","source":"Code4rena — Venus Protocol Isolated Pools Findings & Analysis Report","source_url":"https://code4rena.com/reports/2023-05-venus","date_original":"2023-05-01"},{"date":"2025-02-27","event":"Donation attack exploits Venus Protocol's zkSync deployment, targeting the wUSDM market. Venus absorbs approximately $716,789 in net bad debt. The identical supply-cap bypass mechanism is used. The specific market is patched but no systemic fix is applied across all Venus deployments.","source":"Halborn Security / Rekt News","source_url":"https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026"},{"date":"2025-06","event":"A wallet linked to the future attack begins receiving ETH from Tornado Cash. Over approximately nine months, 7,447 ETH is received across 77 separate Tornado Cash withdrawal transactions. The ETH is deposited on Aave to borrow approximately $9.92 million in stablecoins for THE token accumulation.","source":"BlockSec Blog — Venus Thena Donation Attack","source_url":"https://blocksec.com/blog/venus-thena-donation-attack","date_original":"2025-06-01"},{"date":"2025-06","event":"Gradual accumulation of THE tokens on open markets begins across multiple attacker-controlled addresses. Over nine months the position grows to approximately 12.2 million vTHE tokens, representing 84% of Venus Protocol's 14.5 million THE supply cap.","source":"Venus Community Post-Mortem / BlockSec Blog","source_url":"https://community.venus.io/t/the-market-incident-post-mortem/5712","date_original":"2025-06-01"},{"date":"2026-03-15","event":"At approximately 11:55 UTC, attack contract 0x737bc98f1d34e19539c074b8ad1169d5d45da619 is deployed. Approximately 36.1 million THE are transferred directly to the vTHE contract, inflating the exchange rate 3.81x and bypassing the 14.5 million supply cap. A recursive borrow loop runs from approximately 12:00 to 12:42 UTC, extracting approximately 6.67 million CAKE, 2,801 BNB, 1.58 million USDC, and 20 BTCB. The vTHE collateral position peaks at 53.23 million THE (367% of cap). Venus's Resilient Oracle BoundValidator initially rejects manipulated prices for approximately 37 minutes before accepting THE at approximately $0.51.","source":"Venus Community Post-Mortem / BlockSec Blog","source_url":"https://community.venus.io/t/the-market-incident-post-mortem/5712"},{"date":"2026-03-15","event":"Venus Protocol's risk team detects the exploit and immediately pauses THE borrowing and withdrawals, sets THE collateral factor to zero, and freezes six additional markets (BCH, LTC, UNI, AAVE, FIL, TWT). 8,048 liquidation transactions by 254 unique liquidation bots unwind approximately 42 million THE in collateral, leaving approximately $2.15 million in bad debt.","source":"Venus Community Post-Mortem / BeInCrypto","source_url":"https://beincrypto.com/venus-protocol-exploit-the-token-collateral/"},{"date":"2026-03-15","event":"Emergency governance proposal to freeze approximately $3 million in assets still controlled by the attacker passes, contributing to the attacker's estimated net on-chain loss of $4.71 million.","source":"Rekt News / Venus Community Forum","source_url":"https://rekt.news/venus-protocol-rekt4"},{"date":"2026-03-16","event":"Justin Sun-linked wallets move 621,071 XVS ($1.95 million) to HTX exchange. CoinDesk reports no direct connection to the exploit has been established. XVS governance token declines approximately 9% within 24 hours of public exploit disclosure.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/03/19/venus-xvs-token-plunges-9-as-exploit-leaves-protocol-with-bad-debt"},{"date":"2026-03-17","event":"Venus Protocol publishes official incident post-mortem on the community forum, disclosing attacker addresses, Tornado Cash funding chain, nine-month preparation timeline, and three root-cause factors: supply cap bypass via donation mechanic, price manipulation via thin liquidity, and illiquid collateral concentration risk. Allez Labs announces post-incident risk review.","source":"Venus Community Forum — THE Market Incident Post-Mortem","source_url":"https://community.venus.io/t/the-market-incident-post-mortem/5712"},{"date":"2026-03-19","event":"Venus governance publishes bad-debt repayment proposal for $2,203,024 across 19 affected assets, proposing use of Venus Treasury transfers (CAKE, THE) and Risk Fund transfers (USDT, BNB). Community vote pending. Code-level fix replacing getCashPrior() direct balance read with internalCash state variable is committed.","source":"Venus Community Forum — BNB Chain THE Market Bad Debt Repayment","source_url":"https://community.venus.io/t/bnb-chain-the-market-bad-debt-repayment/5719"}],"sources_used":[{"url":"https://community.venus.io/t/the-market-incident-post-mortem/5712","name":"THE Market Incident Post-Mortem — Venus Community Forum","type":"official","archive_url":"http://web.archive.org/web/20260415063206/https://community.venus.io/t/the-market-incident-post-mortem/5712","credibility":1,"archive_timestamp":"2026-04-15T06:32:06+00:00"},{"url":"https://community.venus.io/t/bnb-chain-the-market-bad-debt-repayment/5719","name":"BNB Chain THE Market Bad Debt Repayment — Venus Community Forum","type":"official","archive_url":"http://web.archive.org/web/20260415074359/https://community.venus.io/t/bnb-chain-the-market-bad-debt-repayment/5719","credibility":1,"archive_timestamp":"2026-04-15T07:43:59+00:00"},{"url":"https://code4rena.com/reports/2023-05-venus","name":"Venus Protocol Isolated Pools Findings & Analysis Report — Code4rena","type":"research","archive_url":"http://web.archive.org/web/20260309064334/https://code4rena.com/reports/2023-05-venus","credibility":1,"archive_timestamp":"2026-03-09T06:43:34+00:00"},{"url":"https://code4rena.com/audits/2023-05-venus-protocol-isolated-pools","name":"Venus Protocol Isolated Pools Audit — Code4rena","type":"research","archive_url":"http://web.archive.org/web/20260708040925/https://code4rena.com/audits/2023-05-venus-protocol-isolated-pools","credibility":1,"archive_timestamp":"2026-07-08T04:09:25+00:00"},{"url":"https://www.coindesk.com/markets/2026/03/19/venus-xvs-token-plunges-9-as-exploit-leaves-protocol-with-bad-debt","name":"Venus' governance token XVS plunges 9% over exploit-driven bad debt — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260320113549/https://www.coindesk.com/markets/2026/03/19/venus-xvs-token-plunges-9-as-exploit-leaves-protocol-with-bad-debt","credibility":1,"archive_timestamp":"2026-03-20T11:35:49+00:00"},{"url":"https://www.theblock.co/post/393622/venus-protocol-left-with-roughly-2m-in-bad-debt-after-exploit-manipulates-thenas-the-token-price","name":"Venus Protocol left with roughly $2M in bad debt after exploit manipulates Thena's THE token price — The Block","type":"news_article","archive_url":"http://web.archive.org/web/20260626111047/https://www.theblock.co/post/393622/venus-protocol-left-with-roughly-2m-in-bad-debt-after-exploit-manipulates-thenas-the-token-price","credibility":1,"archive_timestamp":"2026-06-26T11:10:47+00:00"},{"url":"https://blocksec.com/blog/venus-thena-donation-attack","name":"Venus Thena (THE) Incident: What Broke and What Was Missed — BlockSec Blog","type":"research","archive_url":"http://web.archive.org/web/20260416012900/https://blocksec.com/blog/venus-thena-donation-attack","credibility":2,"archive_timestamp":"2026-04-16T01:29:00+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026","name":"Explained: The Venus Protocol Hack (March 2026) — Halborn Security","type":"research","archive_url":"http://web.archive.org/web/20260528032633/https://www.halborn.com/blog/post/explained-the-venus-protocol-hack-march-2026","credibility":2,"archive_timestamp":"2026-05-28T03:26:33+00:00"},{"url":"https://rekt.news/venus-protocol-rekt4","name":"Venus Protocol - Rekt IV — Rekt News","type":"research","archive_url":"http://web.archive.org/web/20260513155858/https://rekt.news/venus-protocol-rekt4","credibility":2,"archive_timestamp":"2026-05-13T15:58:58+00:00"},{"url":"https://protos.com/venus-protocol-hacker-lost-4-7m-after-nine-months-of-planning/","name":"Venus Protocol hacker lost $4.7M after nine months of planning — Protos","type":"news_article","archive_url":"http://web.archive.org/web/20260416013225/https://protos.com/venus-protocol-hacker-lost-4-7m-after-nine-months-of-planning/","credibility":2,"archive_timestamp":"2026-04-16T01:32:25+00:00"},{"url":"https://www.cryptotimes.io/2026/03/19/donation-attack-on-venus-protocol-leaves-2-15-million-in-bad-debt/","name":"Donation Attack on Venus Protocol Leaves $2.15 Million in Bad Debt — Crypto Times","type":"news_article","archive_url":"http://web.archive.org/web/20260725004013/https://www.cryptotimes.io/2026/03/19/donation-attack-on-venus-protocol-leaves-2-15-million-in-bad-debt/","credibility":2,"archive_timestamp":"2026-07-25T00:40:13+00:00"},{"url":"https://beincrypto.com/venus-protocol-exploit-the-token-collateral/","name":"Venus Freezes 6 Collateral Markets, Thena Finally Speaks Out — BeInCrypto","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.mexc.com/news/venus-protocol-hit-by-3-7m-flash-loan-attack-hacker-prepared-for-9-months/","name":"Venus Protocol Hit By $3.7M Flash Loan Attack: Hacker Prepared For 9 Months — MEXC Blog","type":"news_article","archive_url":"https://web.archive.org/web/20260726190007/https://blog.mexc.com/news/venus-protocol-hit-by-3-7m-flash-loan-attack-hacker-prepared-for-9-months/","credibility":2,"archive_timestamp":"2026-07-26T19:00:07+00:00"},{"url":"https://coinpedia.org/news/venus-protocol-hit-by-3-7m-flash-loan-attack-on-bnb-chain/","name":"Venus Protocol Hit by $3.7M Attack on BNB Chain — CoinPedia","type":"news_article","archive_url":"http://web.archive.org/web/20260416053349/https://coinpedia.org/news/venus-protocol-hit-by-3-7m-flash-loan-attack-on-bnb-chain/","credibility":2,"archive_timestamp":"2026-04-16T05:33:49+00:00"},{"url":"https://www.ainvest.com/news/venus-protocol-exploit-flow-3-7m-illiquid-collateral-risk-2603/","name":"Venus Protocol Exploit: Flow of $3.7M and the Illiquid Collateral Risk — Ainvest","type":"research","archive_url":null,"credibility":2,"archive_error":"forbiddenaccess","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://olympixai.medium.com/venus-protocol-the-market-donation-attack-dfd8f117f92f","name":"Venus Protocol: THE Market Donation Attack — Olympix / Medium","type":"research","archive_url":"https://web.archive.org/web/20260726092937/https://olympixai.medium.com/venus-protocol-the-market-donation-attack-dfd8f117f92f","credibility":2,"archive_timestamp":"2026-07-26T09:29:37+00:00"},{"url":"https://dev.to/ohmygod/the-venus-protocol-donation-attack-how-a-compound-forks-getcashprior-let-an-attacker-bypass-1ggc","name":"The Venus Protocol Donation Attack: getCashPrior() supply cap bypass — DEV Community","type":"research","archive_url":"http://web.archive.org/web/20260329020452/https://dev.to/ohmygod/the-venus-protocol-donation-attack-how-a-compound-forks-getcashprior-let-an-attacker-bypass-1ggc","credibility":2,"archive_timestamp":"2026-03-29T02:04:52+00:00"},{"url":"https://dev.to/ohmygod/the-venus-protocol-donation-attack-how-a-dismissed-audit-finding-became-a-215m-bad-debt-twice-4lk9","name":"Donation Attack: How a Dismissed Audit Finding Became a $2.15M Bad Debt — Twice — DEV Community","type":"research","archive_url":null,"credibility":2,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blockchain.news/flashnews/venus-attacker-transfers-eth-tornado-cash","name":"Venus Attacker Transfers ETH to Tornado Cash — Blockchain.news","type":"on_chain","archive_url":"https://web.archive.org/web/20260726081508/https://blockchain.news/flashnews/venus-attacker-transfers-eth-tornado-cash","credibility":2,"archive_timestamp":"2026-07-26T08:15:08+00:00"},{"url":"https://en.cryptonomist.ch/2026/03/16/venus-protocol-hack-bnb/","name":"Venus Protocol hack triggers $3.7 million loss after THE token manipulation — Cryptonomist","type":"news_article","archive_url":"http://web.archive.org/web/20260725092148/https://en.cryptonomist.ch/2026/03/16/venus-protocol-hack-bnb/","credibility":2,"archive_timestamp":"2026-07-25T09:21:48+00:00"},{"url":"https://quillhashteam.medium.com/200-m-venus-protocol-hack-analysis-b044af76a1ae","name":"$200M Venus Protocol hack analysis — QuillAudits / Medium","type":"research","archive_url":"http://web.archive.org/web/20260705205210/https://quillhashteam.medium.com/200-m-venus-protocol-hack-analysis-b044af76a1ae","credibility":2,"archive_timestamp":"2026-07-05T20:52:10+00:00"},{"url":"https://protos.com/fears-of-27m-venus-protocol-hack-turn-out-to-be-phishing-attack-on-power-user/","name":"Fears of $27M Venus Protocol hack turn out to be phishing attack — Protos","type":"news_article","archive_url":"http://web.archive.org/web/20260508120633/https://protos.com/fears-of-27m-venus-protocol-hack-turn-out-to-be-phishing-attack-on-power-user/","credibility":2,"archive_timestamp":"2026-05-08T12:06:33+00:00"},{"url":"https://www.coingabbar.com/en/crypto-currency-news/venus-protocol-exploit-the-flash-loan-attack-explained","name":"Venus Protocol Exploit: THE Flash Loan Attack Explained — CoinGabbar","type":"news_article","archive_url":"http://web.archive.org/web/20260513032709/https://www.coingabbar.com/en/crypto-currency-news/venus-protocol-exploit-the-flash-loan-attack-explained","credibility":3,"archive_timestamp":"2026-05-13T03:27:09+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-06-07T23:29:45.750922+00:00","updated_at":"2026-07-27T13:22:48.132177+00:00"}}