Venus Protocol, BNB Chain's largest lending platform with $1.47 billion in total value locked, was drained of $3.7 million on March 15, 2026, through a price manipulation and donation attack targeting Thena's THE token. The protocol is left with $2.15 million in bad debt — its fifth major securit...
"The attacker likely generated minimal on-chain profit and potentially suffered net losses." — Weilin Li, On-Chain Security Researcher
Venus Protocol, BNB Chain's largest lending platform with $1.47 billion in total value locked, was drained of $3.7 million on March 15, 2026, through a price manipulation and donation attack targeting Thena's THE token. The protocol is left with $2.15 million in bad debt — its fifth major security incident since 2021, bringing cumulative losses above $112 million.
The attack exploited a vulnerability class that Venus's own Code4rena security audit had identified. The development team disputed the finding at the time, arguing that donations were supported behavior with no negative side effects. An identical attack vector had already cost Venus $700,000 on its ZKSync deployment in February 2025.
The attacker spent nine months preparing the exploit using 7,400 ETH routed through Tornado Cash, yet on-chain analysis suggests the scheme may have been unprofitable — a rare case where both the attacker and the protocol lost.
The exploit began not on March 15 but in June 2025, when a wallet funded with 7,400 ETH withdrawn from Tornado Cash started accumulating Thena's THE token. Over nine months, the attacker amassed approximately 12.2 million THE — 84% of Venus's 14.5 million THE supply cap.
THE, the native token of DeFi protocol Thena, traded at approximately $0.27 before the attack. Its thin on-chain liquidity made it an ideal target: enough value to borrow against on Venus, but not enough market depth to resist price manipulation.
On Sunday, March 15, 2026, the attacker executed. The extracted assets comprised:
Total value: approximately $3.7 million.
The exploit combined two techniques that individually are well-documented but together proved devastating against Venus's risk controls.
Phase 1: Oracle Manipulation Loop. The attacker deposited THE as collateral on Venus, borrowed other assets, used proceeds to buy more THE on the open market, and repeated the cycle. With each iteration, THE's thin liquidity meant the time-weighted average price (TWAP) oracle gradually reflected the artificially inflated price. THE surged from $0.27 to nearly $5 at peak manipulation — an 18x increase.
Phase 2: Donation Attack. To scale beyond Venus's supply cap, the attacker directly transferred 36.1 million THE to the vTHE smart contract rather than depositing through normal minting functions. This inflated the exchange rate by 3.81x, allowing the contract to recognize 53.2 million THE — 367% of the allowed supply cap.
The donation attack is a documented weakness in Compound-forked lending protocols. Direct token transfers to interest-bearing markets distort the internal accounting that governs collateral valuation and supply cap enforcement. The protocol's deposit functions enforce supply caps; direct transfers bypass them entirely.
After the first borrowing cycle, Venus's oracle adjusted THE's recognized price to approximately $0.50 — enough to sustain the borrowing but far below the $5 spot peak. Once the attacker withdrew borrowed assets, THE collapsed to $0.24, below its pre-attack level.
On-chain security researcher Weilin Li, who first flagged the exploit through an automated program that detected a discrepancy between THE's price on centralized and decentralized exchanges, assessed that the attacker "likely generated minimal on-chain profit and potentially suffered net losses."
The math supports this assessment. The attacker's inputs included:
The outputs: $3.7 million in borrowed assets, with THE's post-attack price ($0.24) below its pre-attack level ($0.27), destroying the value of any remaining THE holdings.
Li noted the attacker could have held offsetting perpetual futures positions on external venues — shorting THE on centralized exchanges while pumping it on-chain — but no evidence of this has surfaced. The playbook mirrors the October 2022 Mango Markets exploit, a type of attack Li had modeled in a 2023 academic paper.
The result: Venus lost $2.15 million in unrecoverable bad debt (comprising 1.18 million CAKE tokens and 1.84 million THE tokens), and the attacker likely lost more.
The March 2026 exploit is Venus Protocol's fifth major security incident in five years. The cumulative toll:
| Year | Incident | Loss | |------|----------|------| | 2021 | XVS governance token manipulation | $95 million | | 2022 | Terra/LUNA collapse exposure | $14 million | | 2025 (Feb) | ZKSync deployment donation attack | $700,000 | | 2025 | Phishing attack | $13 million (reported) | | 2026 (Mar) | THE token donation + oracle attack | $3.7 million | | Total | | $112+ million |
Venus's TVL has declined from a peak of approximately $7 billion in 2021 to $1.47 billion as of March 2026 — a 79% contraction. While broader market conditions account for much of this decline, repeated security failures have eroded user confidence and protocol capital.
For context, the $95 million XVS manipulation in 2021 remains one of the largest single-protocol bad debt events in DeFi history. That incident involved Venus's own governance token — a vulnerability class the protocol should have been uniquely positioned to prevent.
The donation attack vector used on March 15 was not novel. It had been:
Despite the February 2025 incident demonstrating the vulnerability in production, the same vector was not fully mitigated on Venus's BNB Chain deployment — the protocol's largest market by TVL. The gap between audit finding, live exploit on a smaller deployment, and repeat exploit on the main deployment spans approximately 12 months.
This pattern — audit identifies risk, team disputes severity, exploit confirms risk — is not unique to Venus. According to CertiK data, oracle manipulation ranked as the number two vulnerability in OWASP's Smart Contract Top 10 for 2025, with oracle-based attacks comprising 13% of DeFi exploits. Over 31% of early 2025 DeFi losses were attributed to oracle-based attacks.
Venus's governance token XVS dropped 9% following the exploit disclosure, according to CoinDesk data as of March 19.
A notable on-chain event added to the governance uncertainty: Justin Sun, Tron founder and a top-5 XVS holder, deposited 621,071 XVS (approximately $1.95 million) to HTX (formerly Huobi) on March 16 — one day after the exploit. The transaction was confirmed on-chain at BNB Chain block 86867468. No direct connection to the exploit has been established, and the move could be coincidental or precautionary. However, a major governance stakeholder moving nearly $2 million in protocol tokens to an exchange immediately after a security incident raises questions about insider confidence.
The timing is structurally significant regardless of intent. Venus operates as a decentralized governance protocol. If top token holders respond to exploits by moving tokens to exchanges — whether to sell, stake, or simply de-risk — it signals that the governance mechanism may not function as a stabilizing force during crises.
Venus is built on Compound's lending architecture, one of the most widely forked codebases in DeFi. The donation attack vulnerability is structural to this architecture: any protocol that allows direct token transfers to interest-bearing markets without corresponding accounting updates is potentially exposed.
The attack raises three questions for the broader Compound-fork ecosystem:
1. Supply cap enforcement. Venus's supply cap was set at 14.5 million THE. The attacker bypassed it entirely through direct transfers. Any Compound fork relying on deposit-function-level supply caps without transfer-level enforcement is similarly exposed.
2. Oracle reliance on thin markets. THE's daily trading volume was insufficient to resist price manipulation by a single well-capitalized actor. Listing low-liquidity tokens as collateral on lending protocols remains a systemic risk that supply caps alone cannot mitigate.
3. Audit follow-through. The disconnect between audit findings, team responses, and remediation timelines is a governance problem, not a technical one. Code4rena identified the risk. Venus disputed it. The ZKSync exploit confirmed it. The BNB Chain exploit repeated it. Twelve months elapsed between identification and repeat exploitation.
The Venus Protocol exploit is notable not for its size — $3.7 million is modest by DeFi exploit standards — but for what it reveals about the industry's relationship with known vulnerabilities. The attack vector was documented, audited, disputed, exploited once on a smaller deployment, and then exploited again on the main deployment. Each step in this sequence represented an opportunity to prevent the final outcome.
The attacker's apparent failure to profit does not reduce the protocol's losses. Venus depositors bear $2.15 million in bad debt. The protocol's governance token lost 9% of its value. And the fifth major incident in five years further erodes whatever trust premium Venus's $1.47 billion TVL still represents.
For the Compound-fork ecosystem, the lesson is architectural: deposit-function supply caps are insufficient when direct token transfers are possible. For DeFi governance broadly, the lesson is procedural: audit findings that are disputed and dismissed become liabilities, not closed items.