Venus Hack
Incident Overview
On March 16, 2026, Venus Protocol on BSC suffered a $2.18M bad debt incident when an attacker exploited a supply cap enforcement gap to bypass the 14.5M THE token limit, accumulating a massive uncapped position over 9 months, then manipulating THE's price from $0.27 to $0.53 through recursive borrowing loops and low DEX liquidity exploitation, before liquidation left $2.18M in unrecoverable debt.
The attacker executed a sophisticated 9-month operation beginning with 7,400 ETH from Tornado Cash, which was deposited into Aave as collateral to borrow $9.92M in stablecoins. The core vulnerability was a supply cap enforcement gap in Venus' legacy code that allowed direct token transfers to the protocol contract, bypassing normal deposit flows and the 14.5M THE supply cap. The attacker slowly accumulated THE tokens and directly transferred them to the vTHE market contract, building a dominant uncapped position. Once established, the attacker executed a recursive attack loop: borrowing assets (CAKE, BNB, BTC), swapping them for THE to pump its price on low-liquidity DEXs, then directly transferring more THE into the vTHE market to inflate the exchange rate. Each iteration increased the collateral value beyond the borrowed amount, generating excess borrowing power to sustain the loop. This manipulation drove THE's price from ~$0.27 to ~$0.53, which the TWAP oracle reflected as designed. The attacker also likely profited from CEX long positions opened before the pump and short positions before dumping THE. When THE crashed after the dump, cascading liquidations occurred on Venus, leaving $2.18M in bad debt ($1.18M CAKE + $1.84M THE) that collateral could not cover.
Blockchain Data Reference
Attacker Wallets:
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Venus, these are the critical security checks that could have prevented this incident (March 2026).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialProof-of-Concept Exploits
On-Chain Evidence & References
Sources & References
Learn to Prevent the Next Venus
The Venus hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.