Volo Hack
Incident Overview
On April 22, 2026, Volo Protocol on Sui suffered a $3.5M exploit affecting three specific vaults containing WBTC, XAUm, and USDC. The team immediately froze all vaults and is working with the Sui Foundation and investigators on recovery. Volo committed to absorbing the loss and confirmed the remaining $28M TVL across other vaults is safe with no shared vulnerability.
An attacker exploited a vulnerability affecting three specific Volo Vaults and removed approximately $3.5M in assets. The stolen funds included WBTC, XAUm, and USDC. Volo detected the attack quickly and took immediate action by notifying the Sui Foundation and ecosystem partners to contain damage. They froze all vaults to prevent further exposure while investigating.
The team confirmed that the exploit was isolated to just these three vaults. The remaining Volo Vaults carry no shared vulnerability and the $28M in TVL across all other vaults remains secure. Volo is working with on-chain investigators and ecosystem partners on potential recovery efforts. The protocol has committed to absorbing the full loss rather than passing it to users.
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Volo, these are the critical security checks that could have prevented this incident (April 2026).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Volo
The Volo hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.