Velar Perps Hack
What happened
An attacker slowly drained Velar's PerpDEX BTC/MUSD perpetual swap pool on Mezo in early 2026. According to Mezo's timeline, the attacker began preparing wallets on 22 January, started moving funds in earnest on 26 January, had finished most of the extraction by 31 January, and wound down on 4 February. Using at least 236 wallets, the attacker pushed about $72 million of trading volume through the contracts. The pool lost about $401,000 (2.257 BTC plus 250,077 MUSD), and the attacker's profit was about $250,000.
Mezo has not confirmed the exact mechanism. It says the pattern closely matches Velar's earlier exploit on Stacks, where the Pyth oracle pulled new prices based on activity, the contracts lacked certain oracle price timestamp checks, and low non-attack activity let the attacker control when prices updated. Mezo says the Redstone oracle Velar used on Mezo behaves in a substantially similar way, and the small gain per trade cycle points to the same method.
Nobody noticed the drain until 19 February, when Gamma, the curator of the Upshift tBTC vault that supplied the pool's liquidity, raised a low balance. Gamma requested signatures to pause deposits and withdrawals from the Upshift tBTC vault on Ethereum, a multisig that includes two Mezo security team members; the pause executed at 19:00 UTC. Mezo removed Velar from its DeFi Hub and Explore page and brought in SEAL 911, which traced the funds from Ethereum to BSC and then to Tornado Cash. On 24 February the Supernormal Foundation announced a recovery token, REKT: 401,300 REKT to be airdropped to the 87 affected wallets, whose value Velar or others can restore over time by buying and burning REKT.
How it happened
- From 22 January 2026 the attacker set up wallet infrastructure, eventually using at least 236 wallets.
- From 26 January the attacker repeated a trade cycle on Velar's BTC/MUSD perp pool: open a long, close it for BTC, open a short with that BTC, close it for MUSD. Each cycle made a small gain.
- Over about $72M of volume, most of it by 31 January and winding down on 4 February, these gains drained about 2.257 BTC and 250,077 MUSD from the pool.
- The proceeds were bridged out and, per SEAL 911, moved from Ethereum to BSC and into Tornado Cash before the drain was discovered on 19 February.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.