← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Venus Protocol's Fifth Exploit Adds to $112M Loss History

Zephyra|March 19, 2026|BPF
EXECUTIVE SUMMARY

Venus Protocol, BNB Chain's largest lending platform with $1.47 billion in total value locked, was drained of $3.7 million on March 15, 2026, through a price manipulation and donation attack targeting Thena's THE token. The protocol is left with $2.15 million in bad debt — its fifth major securit...

"The attacker likely generated minimal on-chain profit and potentially suffered net losses." — Weilin Li, On-Chain Security Researcher

Executive Summary

Venus Protocol, BNB Chain's largest lending platform with $1.47 billion in total value locked, was drained of $3.7 million on March 15, 2026, through a price manipulation and donation attack targeting Thena's THE token. The protocol is left with $2.15 million in bad debt — its fifth major security incident since 2021, bringing cumulative losses above $112 million.

The attack exploited a vulnerability class that Venus's own Code4rena security audit had identified. The development team disputed the finding at the time, arguing that donations were supported behavior with no negative side effects. An identical attack vector had already cost Venus $700,000 on its ZKSync deployment in February 2025.

The attacker spent nine months preparing the exploit using 7,400 ETH routed through Tornado Cash, yet on-chain analysis suggests the scheme may have been unprofitable — a rare case where both the attacker and the protocol lost.

Table of Contents

  1. The Attack: Anatomy of a Nine-Month Setup
  2. Technical Mechanism: Donation Attack Meets Oracle Manipulation
  3. The Attacker's Paradox: $3.7M Extracted, Potentially Net Negative
  4. Venus Protocol's $112 Million Problem
  5. The Audit That Was Ignored
  6. Collateral Damage: XVS Token and Governance Fallout
  7. Implications for Compound-Forked Lending Protocols
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Attack: Anatomy of a Nine-Month Setup

The exploit began not on March 15 but in June 2025, when a wallet funded with 7,400 ETH withdrawn from Tornado Cash started accumulating Thena's THE token. Over nine months, the attacker amassed approximately 12.2 million THE — 84% of Venus's 14.5 million THE supply cap.

THE, the native token of DeFi protocol Thena, traded at approximately $0.27 before the attack. Its thin on-chain liquidity made it an ideal target: enough value to borrow against on Venus, but not enough market depth to resist price manipulation.

On Sunday, March 15, 2026, the attacker executed. The extracted assets comprised:

  • 6.67 million CAKE tokens
  • 1.58 million USDC
  • 2,801 BNB
  • 20 Bitcoin (wrapped as BTCB)

Total value: approximately $3.7 million.

Technical Mechanism: Donation Attack Meets Oracle Manipulation

The exploit combined two techniques that individually are well-documented but together proved devastating against Venus's risk controls.

Phase 1: Oracle Manipulation Loop. The attacker deposited THE as collateral on Venus, borrowed other assets, used proceeds to buy more THE on the open market, and repeated the cycle. With each iteration, THE's thin liquidity meant the time-weighted average price (TWAP) oracle gradually reflected the artificially inflated price. THE surged from $0.27 to nearly $5 at peak manipulation — an 18x increase.

Phase 2: Donation Attack. To scale beyond Venus's supply cap, the attacker directly transferred 36.1 million THE to the vTHE smart contract rather than depositing through normal minting functions. This inflated the exchange rate by 3.81x, allowing the contract to recognize 53.2 million THE — 367% of the allowed supply cap.

The donation attack is a documented weakness in Compound-forked lending protocols. Direct token transfers to interest-bearing markets distort the internal accounting that governs collateral valuation and supply cap enforcement. The protocol's deposit functions enforce supply caps; direct transfers bypass them entirely.

After the first borrowing cycle, Venus's oracle adjusted THE's recognized price to approximately $0.50 — enough to sustain the borrowing but far below the $5 spot peak. Once the attacker withdrew borrowed assets, THE collapsed to $0.24, below its pre-attack level.

The Attacker's Paradox: $3.7M Extracted, Potentially Net Negative

On-chain security researcher Weilin Li, who first flagged the exploit through an automated program that detected a discrepancy between THE's price on centralized and decentralized exchanges, assessed that the attacker "likely generated minimal on-chain profit and potentially suffered net losses."

The math supports this assessment. The attacker's inputs included:

  • 7,400 ETH used to fund initial THE accumulation (worth approximately $13-14 million at time of deployment in June 2025)
  • Nine months of opportunity cost on that capital
  • THE tokens acquired at various prices over the accumulation period

The outputs: $3.7 million in borrowed assets, with THE's post-attack price ($0.24) below its pre-attack level ($0.27), destroying the value of any remaining THE holdings.

Li noted the attacker could have held offsetting perpetual futures positions on external venues — shorting THE on centralized exchanges while pumping it on-chain — but no evidence of this has surfaced. The playbook mirrors the October 2022 Mango Markets exploit, a type of attack Li had modeled in a 2023 academic paper.

The result: Venus lost $2.15 million in unrecoverable bad debt (comprising 1.18 million CAKE tokens and 1.84 million THE tokens), and the attacker likely lost more.

Venus Protocol's $112 Million Problem

The March 2026 exploit is Venus Protocol's fifth major security incident in five years. The cumulative toll:

| Year | Incident | Loss | |------|----------|------| | 2021 | XVS governance token manipulation | $95 million | | 2022 | Terra/LUNA collapse exposure | $14 million | | 2025 (Feb) | ZKSync deployment donation attack | $700,000 | | 2025 | Phishing attack | $13 million (reported) | | 2026 (Mar) | THE token donation + oracle attack | $3.7 million | | Total | | $112+ million |

Venus's TVL has declined from a peak of approximately $7 billion in 2021 to $1.47 billion as of March 2026 — a 79% contraction. While broader market conditions account for much of this decline, repeated security failures have eroded user confidence and protocol capital.

For context, the $95 million XVS manipulation in 2021 remains one of the largest single-protocol bad debt events in DeFi history. That incident involved Venus's own governance token — a vulnerability class the protocol should have been uniquely positioned to prevent.

The Audit That Was Ignored

The donation attack vector used on March 15 was not novel. It had been:

  1. Identified in Venus's Code4rena security audit as a vulnerability class affecting Compound-forked protocols.
  2. Disputed by Venus's development team during the audit process. The team argued that donations were "supported behavior with no negative side effects."
  3. Exploited against Venus's own ZKSync deployment in February 2025, generating $700,000 in bad debt using nearly identical mechanics.

Despite the February 2025 incident demonstrating the vulnerability in production, the same vector was not fully mitigated on Venus's BNB Chain deployment — the protocol's largest market by TVL. The gap between audit finding, live exploit on a smaller deployment, and repeat exploit on the main deployment spans approximately 12 months.

This pattern — audit identifies risk, team disputes severity, exploit confirms risk — is not unique to Venus. According to CertiK data, oracle manipulation ranked as the number two vulnerability in OWASP's Smart Contract Top 10 for 2025, with oracle-based attacks comprising 13% of DeFi exploits. Over 31% of early 2025 DeFi losses were attributed to oracle-based attacks.

Collateral Damage: XVS Token and Governance Fallout

Venus's governance token XVS dropped 9% following the exploit disclosure, according to CoinDesk data as of March 19.

A notable on-chain event added to the governance uncertainty: Justin Sun, Tron founder and a top-5 XVS holder, deposited 621,071 XVS (approximately $1.95 million) to HTX (formerly Huobi) on March 16 — one day after the exploit. The transaction was confirmed on-chain at BNB Chain block 86867468. No direct connection to the exploit has been established, and the move could be coincidental or precautionary. However, a major governance stakeholder moving nearly $2 million in protocol tokens to an exchange immediately after a security incident raises questions about insider confidence.

The timing is structurally significant regardless of intent. Venus operates as a decentralized governance protocol. If top token holders respond to exploits by moving tokens to exchanges — whether to sell, stake, or simply de-risk — it signals that the governance mechanism may not function as a stabilizing force during crises.

Implications for Compound-Forked Lending Protocols

Venus is built on Compound's lending architecture, one of the most widely forked codebases in DeFi. The donation attack vulnerability is structural to this architecture: any protocol that allows direct token transfers to interest-bearing markets without corresponding accounting updates is potentially exposed.

The attack raises three questions for the broader Compound-fork ecosystem:

1. Supply cap enforcement. Venus's supply cap was set at 14.5 million THE. The attacker bypassed it entirely through direct transfers. Any Compound fork relying on deposit-function-level supply caps without transfer-level enforcement is similarly exposed.

2. Oracle reliance on thin markets. THE's daily trading volume was insufficient to resist price manipulation by a single well-capitalized actor. Listing low-liquidity tokens as collateral on lending protocols remains a systemic risk that supply caps alone cannot mitigate.

3. Audit follow-through. The disconnect between audit findings, team responses, and remediation timelines is a governance problem, not a technical one. Code4rena identified the risk. Venus disputed it. The ZKSync exploit confirmed it. The BNB Chain exploit repeated it. Twelve months elapsed between identification and repeat exploitation.

Key Takeaways

  • Venus Protocol lost $3.7 million on March 15, 2026, to a combined donation attack and oracle manipulation targeting Thena's THE token. Bad debt stands at $2.15 million.
  • The attacker spent nine months and at least 7,400 ETH preparing the exploit but likely generated minimal or negative on-chain returns.
  • This is Venus's fifth major security incident since 2021, pushing cumulative losses above $112 million. TVL has contracted 79% from its $7 billion peak.
  • The donation attack vector was identified in Venus's own Code4rena audit and exploited on its ZKSync deployment 12 months prior. The team disputed the audit finding's severity.
  • XVS dropped 9% post-exploit. Justin Sun, a top-5 holder, moved $1.95 million in XVS to HTX one day after the incident.
  • Oracle manipulation remains the second-most-common DeFi exploit vector, accounting for 13% of all DeFi exploits in 2025.

Conclusion

The Venus Protocol exploit is notable not for its size — $3.7 million is modest by DeFi exploit standards — but for what it reveals about the industry's relationship with known vulnerabilities. The attack vector was documented, audited, disputed, exploited once on a smaller deployment, and then exploited again on the main deployment. Each step in this sequence represented an opportunity to prevent the final outcome.

The attacker's apparent failure to profit does not reduce the protocol's losses. Venus depositors bear $2.15 million in bad debt. The protocol's governance token lost 9% of its value. And the fifth major incident in five years further erodes whatever trust premium Venus's $1.47 billion TVL still represents.

For the Compound-fork ecosystem, the lesson is architectural: deposit-function supply caps are insufficient when direct token transfers are possible. For DeFi governance broadly, the lesson is procedural: audit findings that are disputed and dismissed become liabilities, not closed items.

Sources & References

  1. Donation Attack on Venus Protocol Leaves $2.15 Million in Bad Debt — CryptoTimes, March 19, 2026
  2. Venus Protocol left with roughly $2M in bad debt after exploit manipulates Thena's THE token price — The Block, March 2026
  3. Venus Protocol hack triggers $3.7 million loss after THE token manipulation on BNB Chain — The Cryptonomist, March 16, 2026
  4. Venus' governance token XVS plunges 9% over exploit-driven bad debt — CoinDesk, March 19, 2026
  5. Venus Protocol Suffers $3.7M Loss in Thena Token Price Manipulation Attack — Parameter, March 2026
  6. Venus Protocol Suffers $3.7M Loss in Thena (THE) Token Price Manipulation Attack — Blockonomi, March 2026
  7. Venus Protocol Hit by $3.7M Supply Cap Attack, Key Markets Paused — CryptoTimes, March 16, 2026
  8. Venus Protocol hacker lost $4.7M after nine months of planning — Protos, March 2026
  9. Dormant Wallet Linked to Justin Sun Moves 621K XVS — CoinFomania, March 2026
  10. Oracle Wars: The Rise of Price Manipulation Attacks — CertiK, 2025