Venus Protocol, BNB Chain's largest lending platform with $1.47 billion in total value locked, lost $3.7 million on March 15 after an attacker spent nine months preparing a donation attack against its Thena (THE) token market. The exploit left approximately $2.15 million in bad debt — loans the p...
"The donation attack vector had been discussed in Venus's own Code4rena security audit, but the team disputed the finding at the time, arguing that donations were supported behavior with no negative side effects." — Venus Protocol Post-Mortem, March 2026
Venus Protocol, BNB Chain's largest lending platform with $1.47 billion in total value locked, lost $3.7 million on March 15 after an attacker spent nine months preparing a donation attack against its Thena (THE) token market. The exploit left approximately $2.15 million in bad debt — loans the protocol can no longer recover.
The attack method was not novel. It had been flagged in Venus's own Code4rena security audit as a known vulnerability in Compound V2-forked protocols. The team disputed and dismissed the finding. A near-identical attack hit Venus's own zkSync deployment in February 2025, causing $700,000 in bad debt. The same structural flaw was exploited in the Hundred Finance hack of April 2023 ($7.4 million loss) and Sonne Finance ($20 million loss). Venus has now absorbed over $112 million in bad debt across four incidents since 2021.
The attacker began preparations in June 2025. A connected wallet received 7,447 ETH (approximately $16.29 million at the time) from Tornado Cash, the Ethereum mixing protocol. Those funds were deposited into Aave, where the attacker borrowed approximately $9.92 million in stablecoins to purchase THE tokens.
Over the following nine months, the attacker accumulated approximately 12.2 million THE tokens — 84% of Venus Protocol's 14.5 million supply cap for the asset. The accumulation was slow and deliberate, avoiding sudden price spikes that would trigger monitoring alerts. No automated system flagged the concentration.
At no point during this period did Venus's risk management infrastructure identify that a single entity controlled the vast majority of a collateral market's supply cap.
The attack executed on March 15, 2026 at approximately 11:55 UTC in a single transaction (0x4f477e...).
Phase 1 — Exchange Rate Inflation (11:55 UTC). Six wallets transferred approximately 36 million THE directly to the vTHE smart contract. This bypassed the mint() function entirely, inflating the exchange rate by 3.81x without increasing the token's supply count. THE price spiked from approximately $0.26 to nearly $4 on the Binance Oracle feed. Venus's BoundValidator reverted for approximately 37 minutes.
Phase 2 — Borrow-Swap-Donate Loop (12:00–12:42 UTC). The attack contract borrowed 1.58 million USDC, 4.6 million THE, 910,000 CAKE, and 1,972 BNB against the inflated collateral. The attacker then executed repeated borrow → swap → donate loops: borrowing 100 BNB per cycle, swapping to THE, and directing funds back to the vTHE contract. By peak, THE supply in the contract reached 53.23 million — 367% of the designated cap.
Phase 3 — Collapse (12:42 UTC onward). THE price collapsed to approximately $0.22 as liquidation cascades unwound roughly 42 million in collateral. The protocol was left with $2.15 million in bad debt (1.18 million CAKE tokens and 1.84 million THE equivalent).
Total assets extracted: 6.67 million CAKE, 1.58 million USDC, 2,801 BNB, and 20 Bitcoin. On-chain analyst Weilin Li noted the attacker may have incurred net losses due to slippage, though this remains contested.
The vulnerability is structural and well-documented. In Compound V2 and its forks, the exchange rate between collateral tokens (cTokens/vTokens) and underlying assets is calculated as:
exchangeRate = (totalCash + totalBorrows - totalReserves) / totalSupply
The mint() function enforces supply cap checks before accepting deposits. However, direct ERC-20 token transfers to the contract address bypass this function entirely. The contract reads its own balance via getCashPrior(), so donated tokens inflate totalCash without incrementing totalSupply. The exchange rate rises accordingly, and existing vToken holders suddenly have inflated collateral value.
Three defensive layers failed simultaneously:
mint() pathway, not direct transfers.The fix is conceptually simple: enforce supply cap checks on all balance increases to the market contract, not only the mint pathway. Venus has committed to implementing this in its remediation plan.
The immediate financial damage:
| Metric | Value | |---|---| | Total assets extracted | $3.7M | | Bad debt remaining | $2.15M | | THE price (pre-attack) | ~$0.26 | | THE price (peak) | ~$4.00 | | THE price (post-collapse) | ~$0.22 | | XVS governance token decline | -9% | | Markets paused | 10 (THE, CAKE, BCH, LTC, UNI, AAVE, POL, FIL, TWT, lisUSD) |
Justin Sun, Tron founder and top-5 XVS holder, deposited 621,071 XVS (approximately $1.95 million) to HTX exchange on March 16 — one day after the exploit. On-chain analysis from multiple firms characterized the move as a dormant-wallet relocation rather than a liquidation, though the timing prompted speculation.
Thena issued a statement on March 18 clarifying its own protocol was not compromised: "THENA's smart contracts and all liquidity pools remain secure and fully operational." The incident originated entirely within Venus Protocol's lending markets.
Venus Protocol has a documented history of bad debt events:
| Date | Incident | Bad Debt | |---|---|---| | May 2021 | XVS token manipulation | $95M+ | | May 2022 | Terra/LUNA collapse exposure | $14M | | Feb 2025 | zkSync donation attack (THE) | $700K | | Mar 2026 | BNB Chain donation attack (THE) | $2.15M | | Total | | $112M+ |
The donation attack vector was flagged in Venus's Code4rena security audit. According to the protocol's own post-mortem, the team "disputed the finding at the time, arguing that donations were supported behavior with no negative side effects." Thirteen months later, the identical vector was exploited on the same protocol's zkSync deployment. Six months after that, it was exploited again on BNB Chain at larger scale.
Two liquidated users have publicly requested compensation from Venus's Risk Fund, arguing that losses from known, audit-flagged vulnerabilities should not fall on individual depositors.
The Venus exploit is not an isolated incident. Donation attacks represent a known vulnerability class affecting the entire ecosystem of Compound V2 forks. According to data from Sentora, lending protocols logged 67 exploits out of 267 total DeFi incidents tracked over the past 12 months through January 2026. Price manipulation incidents accounted for 13 of those, totaling $65 million in losses.
Notable Compound-fork donation attacks:
Lending protocols collectively hold $53 billion in reported value locked, according to Sentora. Audited protocols lost $515 million over the past year — demonstrating that audit completion alone does not guarantee security, particularly when audit findings are disputed and left unresolved.
Venus has outlined a three-phase response:
Immediate (completed): Paused borrowing and withdrawals across 10 collateral markets. Flagged attacker addresses for forensic investigation. Implemented automated concentration monitoring.
Short-term (in progress): Enforce supply cap checks on all balance increases, not only the mint pathway. Audit and reduce collateral factors for illiquid assets. Submit governance proposal for bad debt resolution via the Risk Fund. Coordinate with law enforcement regarding Tornado Cash-sourced funds.
Mid-term (planned): Complete re-audit of the core lending pool. Review all Compound V2-inherited code paths for similar bypass vectors.
The governance community must now decide whether the $2.15 million in bad debt will be absorbed by the protocol's Risk Fund — and whether liquidated users will receive any compensation.
The Venus Protocol donation attack was predictable, preventable, and had been explicitly flagged in a prior security audit. The attacker spent nine months preparing, accumulated 84% of a collateral market's supply cap without triggering alerts, and exploited a code path that any Compound V2 fork operator should treat as a known risk.
The $2.15 million in bad debt is manageable for a $1.47 billion protocol. The reputational damage of ignoring a flagged vulnerability — twice — is harder to quantify. With lending protocols absorbing 67 exploits in the past year and $53 billion in collective TVL at stake, the Venus incident serves as a reminder that the most expensive vulnerabilities are not the ones you discover, but the ones you dismiss.