{"investigation":{"slug":"volo-vault","entity_name":"Volo Vault","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Volo Vault is a yield-generating vault product operated by Volo Protocol, a BTCFi and liquid staking platform built on the Sui blockchain. In April 2026, three of its vaults were exploited via a compromised admin private key, resulting in approximately $3.5 million in losses across WBTC, XAUm, and USDC holdings. The team committed to absorbing all user losses and ultimately recovered approximately 90% of the stolen funds through coordination with the Sui Foundation, ZachXBT, and ecosystem partners.","sections":[{"content":"On April 21–22, 2026, an attacker drained approximately $3.5 million from three Volo Vault contracts on the Sui blockchain. The affected vaults held wrapped bitcoin (WBTC, approximately $2.1 million), Matrixdock tokenized gold (XAUm, approximately $0.9 million), and USDC (approximately $0.5 million). Security firms GoPlus Security and ExVul attributed the root cause to a compromised vault admin private key obtained through alleged social engineering, not a flaw in Volo's audited smart contracts. The attacker invoked the privileged function `withdraw_with_account_cap_v2` to drain the three isolated vaults. The attacker address identified on-chain was 0xe76970bbf9b038974f6086009799772db5190f249ce7d065a581b1ac0adaef75. The remaining roughly $28 million in TVL across unaffected vaults was confirmed safe, with no shared vulnerability identified. This incident was flagged by on-chain investigator ZachXBT.","heading":"Security Exploit — April 2026","sources":[{"url":"https://news.bitcoin.com/volo-protocol-loses-3-5-million-in-sui-blockchain-exploit-blocks-wbtc-bridge-attempt/","name":"news.bitcoin.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/volo-defi-3-5m-exploit-vault-attack-recovery","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2026/04/22/another-defi-protocol-loses-millions-in-hack-days-after-kelpdao-breach","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.banklesstimes.com/articles/2026/04/22/volo-protocol-confirms-3-5m-sui-vault-exploit-500k-already-frozen/","name":"banklesstimes.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Within approximately 30 minutes of the breach becoming known, Volo and ecosystem partners froze roughly $500,000 of stolen assets. On April 22, 2026, the team successfully blocked an attempt by the attacker to bridge out 19.6 WBTC (approximately $2.1 million), with those funds placed under the custody of cooperating platforms pending return. By April 27, 2026, Volo reported that roughly 90% of the stolen $3.5 million had been recovered or frozen, leaving a net loss of approximately $200,000. Volo publicly committed to absorbing all remaining losses from its Treasury and pledged full compensation to affected depositors. The team stated the existing Treasury balance was sufficient to cover the shortfall without passing losses to users. A comprehensive compensation mechanism and post-mortem report were announced as pending. TVL declined only marginally from $15.83 million to $15.27 million in the immediate aftermath, suggesting limited user flight.","heading":"Recovery and Compensation","sources":[{"url":"https://phemex.com/news/article/volo-recovers-90-of-stolen-funds-after-35m-exploit-76447","name":"phemex.com","type":"other","credibility":3},{"url":"https://themarketperiodical.com/2026/04/23/crypto-hack-volo-recovers-2m-of-exploited-funds/","name":"themarketperiodical.com","type":"other","credibility":3},{"url":"https://thecurrencyanalytics.com/stable-coins/volo-protocol-loses-3-5-million-in-vault-exploit-team-pledges-full-user-reimbursement-254311","name":"thecurrencyanalytics.com","type":"other","credibility":3},{"url":"https://finance.yahoo.com/markets/crypto/articles/sui-crypto-defi-protocol-volo-154550226.html","name":"finance.yahoo.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit exposed a significant centralization risk inherent in Volo Vault's architecture: the existence of a privileged admin key capable of directly withdrawing vault funds without user consent. GoPlus Security and ExVul both confirmed that the breach was not attributable to flaws in the audited smart contract code but rather to the compromise of this operator credential through alleged social engineering. The use of a privileged withdrawal function (`withdraw_with_account_cap_v2`) indicates that vault operations retained a degree of centralized control inconsistent with fully trustless DeFi design. This is a structural risk factor that persists regardless of smart contract audit outcomes. The post-mortem had not been published as of the date of this investigation.","heading":"Admin Key and Centralization Risk","sources":[{"url":"https://news.bitcoin.com/volo-protocol-loses-3-5-million-in-sui-blockchain-exploit-blocks-wbtc-bridge-attempt/","name":"news.bitcoin.com","type":"other","credibility":3},{"url":"https://www.cryptobreaking.com/volo-exploit-raises-security-concerns/","name":"cryptobreaking.com","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/63a0c-volo-protocol-sui-exploit-details","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the April 2026 exploit, Volo Protocol's smart contracts were audited by Ottersec, Movebit, and Hacken. The protocol also maintained an active bug bounty program. A separate audit of the NAVI-Volo Vault v3 contracts was conducted by Veridise in November 2025, producing a formal methods report (VAR-NAVI-250523-SUI-VOLO-VAULT-V3). The April 2026 breach did not stem from any vulnerability identified by these audits; the compromise was attributed to an off-chain credential leak, not on-chain code flaws. The existence of multiple audits from reputable firms reduces smart contract risk but does not mitigate operational security risks related to key management.","heading":"Audit History","sources":[{"url":"https://news.bitcoin.com/volo-protocol-loses-3-5-million-in-sui-blockchain-exploit-blocks-wbtc-bridge-attempt/","name":"news.bitcoin.com","type":"other","credibility":3},{"url":"https://veridise.com/wp-content/uploads/2025/11/VAR-NAVI-250523-SUI-VOLO-VAULT-V3.pdf","name":"veridise.com","type":"other","credibility":3},{"url":"https://medium.com/@navi.protocol/navi-protocol-acquires-liquid-staking-protocol-volo-55ca7925f7c9","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Volo was founded as a dedicated liquid staking platform for SUI tokens, allowing users to stake SUI and receive a liquid derivative token (vSUI) that could be deployed across broader DeFi strategies. The project won top honors at the Sui Foundation's Liquid Staking Hackathon. In January 2024, NAVI Protocol — described as the leading liquidity protocol on Sui — announced the acquisition of Volo, with integration expected within one month. At the time of acquisition, Volo had approximately $7.45 million in TVL. Following the acquisition, the Volo team joined NAVI and the combined entity began offering merged borrowing, lending, and liquid staking services. No specific founders or individual team members have been publicly identified in available sources.","heading":"Corporate History and NAVI Acquisition","sources":[{"url":"https://medium.com/@navi.protocol/navi-protocol-acquires-liquid-staking-protocol-volo-55ca7925f7c9","name":"medium.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/volo","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Volo exploit occurred during an unusually active period for DeFi security incidents. KelpDAO was exploited for approximately $292 million on April 18, 2026, and Drift Protocol for approximately $285 million in the same month. Industry estimates placed total crypto losses in April 2026 in excess of $600 million. The Volo breach contributed to heightened scrutiny of security practices across Sui's DeFi ecosystem, which held approximately $1.2 billion in total value locked at the time. The incident illustrates a broader trend of attackers targeting access controls and key management rather than audited contract code.","heading":"Broader DeFi Context","sources":[{"url":"https://www.coindesk.com/markets/2026/04/22/another-defi-protocol-loses-millions-in-hack-days-after-kelpdao-breach","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.cryptobreaking.com/volo-exploit-raises-security-concerns/","name":"cryptobreaking.com","type":"other","credibility":3},{"url":"https://ambcrypto.com/volo-protocol-suffers-3-5-mln-exploit-in-aprils-third-crypto-hacking-incident/","name":"ambcrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"No SEC, CFTC, DOJ, or other regulatory enforcement actions against Volo Protocol or Volo Vault have been identified in publicly available records as of May 2026. No court filings related to the April 2026 exploit have been located. The protocol has not been added to any OFAC sanctions list. Absence of regulatory action does not constitute regulatory clearance, particularly given the ongoing nature of the post-mortem investigation.","heading":"Regulatory Status","sources":[],"severity":"medium"}],"timeline":[{"date":"2024-01-17","event":"NAVI Protocol announces acquisition of Volo liquid staking protocol; Volo TVL at $7.45 million at time of announcement.","source":""},{"date":"2025-08-07","event":"Volo launches BTC Vaults, enabling users to earn yield on wrapped Bitcoin (wBTC) on Sui.","source":""},{"date":"2025-11","event":"Veridise completes formal audit of NAVI-Volo Vault v3 smart contracts (VAR-NAVI-250523-SUI-VOLO-VAULT-V3).","source":"","date_original":"2025-11-01"},{"date":"2026-04-21","event":"Attacker uses compromised admin private key to invoke privileged withdrawal function, draining three Volo Vaults of approximately $3.5 million in WBTC, XAUm, and USDC. Attacker address: 0xe76970bbf9b038974f6086009799772db5190f249ce7d065a581b1ac0adaef75.","source":""},{"date":"2026-04-22","event":"Volo freezes all vaults and publicly confirms the exploit. Approximately $500,000 frozen within 30 minutes. Team notifies Sui Foundation and engages ZachXBT and ecosystem partners. Team commits to absorbing all user losses.","source":""},{"date":"2026-04-22","event":"Volo successfully blocks attacker's attempt to bridge out 19.6 WBTC (approximately $2.1 million); funds held by cooperating platforms.","source":""},{"date":"2026-04-22","event":"GoPlus Security and ExVul publish analysis attributing root cause to social-engineering-based admin key compromise, not smart contract vulnerability.","source":""},{"date":"2026-04-27","event":"Volo reports approximately 90% of stolen funds recovered or frozen; net loss estimated at approximately $200,000. Full user compensation pledged from Treasury.","source":""}],"sources_used":[{"url":"https://news.bitcoin.com/volo-protocol-loses-3-5-million-in-sui-blockchain-exploit-blocks-wbtc-bridge-attempt/","name":"news.bitcoin.com","type":"other","archive_url":"http://web.archive.org/web/20260423140853/https://news.bitcoin.com/volo-protocol-loses-3-5-million-in-sui-blockchain-exploit-blocks-wbtc-bridge-attempt/","credibility":3,"archive_timestamp":"2026-04-23T14:08:53+00:00"},{"url":"https://cointelegraph.com/news/volo-defi-3-5m-exploit-vault-attack-recovery","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260521040806/https://cointelegraph.com/news/volo-defi-3-5m-exploit-vault-attack-recovery","credibility":3,"archive_timestamp":"2026-05-21T04:08:06+00:00"},{"url":"https://www.coindesk.com/markets/2026/04/22/another-defi-protocol-loses-millions-in-hack-days-after-kelpdao-breach","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260423052928/https://www.coindesk.com/markets/2026/04/22/another-defi-protocol-loses-millions-in-hack-days-after-kelpdao-breach","credibility":3,"archive_timestamp":"2026-04-23T05:29:28+00:00"},{"url":"https://www.banklesstimes.com/articles/2026/04/22/volo-protocol-confirms-3-5m-sui-vault-exploit-500k-already-frozen/","name":"banklesstimes.com","type":"other","archive_url":"http://web.archive.org/web/20260515130801/https://www.banklesstimes.com/articles/2026/04/22/volo-protocol-confirms-3-5m-sui-vault-exploit-500k-already-frozen/","credibility":3,"archive_timestamp":"2026-05-15T13:08:01+00:00"},{"url":"https://phemex.com/news/article/volo-recovers-90-of-stolen-funds-after-35m-exploit-76447","name":"phemex.com","type":"other","archive_url":"https://web.archive.org/web/20260829230638/https://phemex.com/news/article/volo-recovers-90-of-stolen-funds-after-35m-exploit-76447","credibility":3,"archive_timestamp":"2026-08-29T23:06:38+00:00"},{"url":"https://themarketperiodical.com/2026/04/23/crypto-hack-volo-recovers-2m-of-exploited-funds/","name":"themarketperiodical.com","type":"other","archive_url":"https://web.archive.org/web/20260829082501/https://themarketperiodical.com/ru/2026/08/29/etf-bitwise-solana-%d0%bf%d1%80%d0%b5%d0%be%d0%b4%d0%be%d0%bb%d0%b5%d0%bb-%d1%80%d1%83%d0%b1%d0%b5%d0%b6-%d0%b2-1-%d0%bc%d0%b8%d0%bb%d0%bb%d0%b8%d0%b0%d1%80%d0%b4-%d0%b4%d0%be%d0%bb%d0%bb%d0%b0%d1%80/?tdb_action=tdb_ajax","credibility":3,"archive_timestamp":"2026-08-29T08:25:01+00:00"},{"url":"https://thecurrencyanalytics.com/stable-coins/volo-protocol-loses-3-5-million-in-vault-exploit-team-pledges-full-user-reimbursement-254311","name":"thecurrencyanalytics.com","type":"other","archive_url":"http://web.archive.org/web/20260726150031/https://thecurrencyanalytics.com/stable-coins/volo-protocol-loses-3-5-million-in-vault-exploit-team-pledges-full-user-reimbursement-254311","credibility":3,"archive_timestamp":"2026-07-26T15:00:31+00:00"},{"url":"https://finance.yahoo.com/markets/crypto/articles/sui-crypto-defi-protocol-volo-154550226.html","name":"finance.yahoo.com","type":"other","archive_url":"http://web.archive.org/web/20260429151428/https://finance.yahoo.com/markets/crypto/articles/sui-crypto-defi-protocol-volo-154550226.html","credibility":3,"archive_timestamp":"2026-04-29T15:14:28+00:00"},{"url":"https://www.cryptobreaking.com/volo-exploit-raises-security-concerns/","name":"cryptobreaking.com","type":"other","archive_url":"http://web.archive.org/web/20260519103227/https://www.cryptobreaking.com/volo-exploit-raises-security-concerns/","credibility":3,"archive_timestamp":"2026-05-19T10:32:27+00:00"},{"url":"https://cryptorank.io/news/feed/63a0c-volo-protocol-sui-exploit-details","name":"cryptorank.io","type":"other","archive_url":"http://web.archive.org/web/20260726223738/https://cryptorank.io/news/feed/63a0c-volo-protocol-sui-exploit-details","credibility":3,"archive_timestamp":"2026-07-26T22:37:38+00:00"},{"url":"https://veridise.com/wp-content/uploads/2025/11/VAR-NAVI-250523-SUI-VOLO-VAULT-V3.pdf","name":"veridise.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://medium.com/@navi.protocol/navi-protocol-acquires-liquid-staking-protocol-volo-55ca7925f7c9","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/volo","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20251018234143/https://defillama.com/protocol/volo","credibility":3,"archive_timestamp":"2025-10-18T23:41:43+00:00"},{"url":"https://ambcrypto.com/volo-protocol-suffers-3-5-mln-exploit-in-aprils-third-crypto-hacking-incident/","name":"ambcrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260423115714/https://ambcrypto.com/volo-protocol-suffers-3-5-mln-exploit-in-aprils-third-crypto-hacking-incident/","credibility":3,"archive_timestamp":"2026-04-23T11:57:14+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:16.895036+00:00","updated_at":"2026-08-29T23:26:11.305468+00:00"}}