🚨 The lending protocol Venus Protocol has been attacked once again.

CN
BITWU.ETH
Follow
13 hours ago

🚨 The lending protocol Venus Protocol has been attacked once again, resulting in a loss of approximately $30 million.

Looking back, Venus @VenusProtocol has had a tumultuous journey. Since its establishment in 2020, it has suffered six major security incidents, with total losses exceeding $140 million—

1⃣ In May 2021, XVS price manipulation + excessive borrowing (bad debt of $100 million)

Attackers quickly inflated the XVS price to $145 via PancakeSwap, then used the overvalued XVS as collateral to borrow large amounts of BTC and ETH; after the XVS price fell, a series of liquidations were triggered, leading to significant bad debt for the protocol.

2⃣ In May 2022, LUNA oracle distortion (loss of $11 million)

During the collapse of the LUNA ecosystem, Chainlink suspended LUNA price feeds, while Venus continued to use the outdated price of $0.107, even though the actual value of LUNA had nearly reached zero.

3⃣ In December 2023, SnBNB oracle manipulation (loss of $270,000)

The PancakeSwap v3 shallow pool was inflated, pushing the Binance Oracle price to $77B, and the attacker drained Venus's LST pool, resulting in a loss of $270,000.

4⃣ In February 2024, wUSDM oracle manipulation (loss of $716,000)

The attacker used a flash loan to inject funds into the wUSDM Vault, manipulating the wUSDM price from $1.06 to $1.7, and then self-liquidated on Venus Protocol using two accounts.

5⃣ In June 2025, MEV exploitation (loss of $2 million)

The attacker exploited a vulnerability in the permission management system to carry out the attack.

What is the reason today?

I saw @evilcos mention that a large holder was phished, and the hacker gained admin privileges, pointing the Comptroller proxy to a malicious implementation contract.

Withdrawals have currently been suspended, awaiting a detailed report!

A DeFi protocol experiencing such incidents frequently is quite damaging to its brand; at least for the short term, I wouldn't dare to invest my money in it…

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

奖池$20K!交易$20上榜,注册送$1,500
Ad
Share To
APP

X

Telegram

Facebook

Reddit

CopyLink