Volo Hack

TOTAL LOST $3.5M
Medium Other

What happened

On April 22, 2026, Volo Protocol on Sui suffered a $3.5M exploit affecting three specific vaults containing WBTC, XAUm, and USDC. The team immediately froze all vaults and is working with the Sui Foundation and investigators on recovery. Volo committed to absorbing the loss and confirmed the remaining $28M TVL across other vaults is safe with no shared vulnerability.

An attacker exploited a vulnerability affecting three specific Volo Vaults and removed approximately $3.5M in assets. The stolen funds included WBTC, XAUm, and USDC. Volo detected the attack quickly and took immediate action by notifying the Sui Foundation and ecosystem partners to contain damage. They froze all vaults to prevent further exposure while investigating.

The team confirmed that the exploit was isolated to just these three vaults. The remaining Volo Vaults carry no shared vulnerability and the $28M in TVL across all other vaults remains secure. Volo is working with on-chain investigators and ecosystem partners on potential recovery efforts. The protocol has committed to absorbing the full loss rather than passing it to users.

Case & protocol details

Classification Yield Aggregator
Protocol Type Exploit/Other
Official Website www.volosui.com/
Protocol Twitter/X @volo_sui

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.