Venus Hack
Incident Overview
On September 2, 2025, a Venus Protocol user fell victim to a phishing attack involving a malicious Zoom client, losing approximately $13 million after signing a transaction that granted the attacker delegate approval. Venus Protocol paused operations within 20 minutes of detection and successfully recovered all stolen funds within 13 hours through a coordinated liquidation strategy.
The attack began when the victim was compromised through a malicious Zoom client that gave attackers privileges on their machine. The attackers exploited this access to trick the victim into signing a phishing transaction that approved the attacker as a valid Venus delegate, allowing them to borrow and redeem on the victim's behalf. The attacker executed a complex multi-step exploit: sourcing 285.72 BTCB via flash loan, repaying the victim's 306.89 BTCB debt, transferring approximately $13M in deposits (19.826M USDT, 3,744 wBETH, 311,571 FDUSD, ~15k USDC, and ETH) to their contract, borrowing $7.14M USDC against the victim's remaining BNB collateral, and repaying the flash loan with stolen assets.
Venus Protocol responded rapidly by pausing core actions within 20 minutes, conducting thorough security reviews, and implementing a recovery plan through community governance. The team executed a coordinated liquidation strategy that seized 100% of the attacker's collateral, transferred stolen assets to a receiver wallet, and cleared the attacker's debt while transferring it to the receiver, successfully recovering all funds.
Exploit tx:
https://bscscan.com/tx/0x75eee705…9be0e2
Victim: 0x563617b8…b52008
Attacker: 0x7fd8f825…a6202a
Receiver: 0xC753FB97…2232FA
Custom Liquidator: 0xe011d57e…886c50
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Venus, these are the critical security checks that could have prevented this incident (September 2025).
- Verify all logic paths related to Phishing are guarded by proper access controls and input validation - see the Phishing Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$13.0M
Net Loss
0
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next Venus
The Venus hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.