BNB Chain Lending Protocol Venus Protocol experienced a carefully planned supply cap exploit on March 16. The hacker spent 9 months gradually building a position, manipulating THE token prices, and triggering a series of liquidations, ultimately extracting about $5.07 million in assets and leaving $2.15 million in bad debt.
(Background: BNB hacker nearly liquidated $200 million; Venus: BNB Chain official will “take over positions”)
(Additional context: Research | Common DeFi economic model attacks: token price manipulation, oracle errors, leverage liquidations)
Table of Contents
Toggle
- Attack Timeline: 9 months lurking, 40 minutes harvesting
- Results: $5.07 million withdrawn, $2.15 million in bad debt
- Venus Emergency Response: 7 market collateral factors set to zero
On March 16, Venus Protocol, a leading lending protocol on BNB Chain, was subjected to a meticulously planned attack that lasted nine months. After obtaining funds via Tornado Cash, the hacker manipulated the low-liquidity THE (Thena native token) price, triggering a chain of liquidations, resulting in approximately $2.15 million in bad debt for the protocol. The hacker then withdrew about $5.07 million in assets, with potential profits even higher.
Attack Timeline: 9 months lurking, 40 minutes harvesting
A wallet address, “0x7a7,” which received 7,447 ETH (about $16.29 million) from Tornado Cash, has been identified by on-chain researchers as the mastermind behind the attack.
The attack was carried out in two phases:
- Long-term lurking (starting June 2025): The attacker used normal deposit processes to slowly accumulate THE tokens on Venus, eventually holding 84% of the protocol’s supply cap (about 12.2 million tokens).
- The day of the attack (about 40 minutes): Using ETH as collateral on Aave, the attacker borrowed $9.92 million stablecoins, and heavily accumulated THE tokens on centralized exchanges, likely to pump the spot price; simultaneously, they transferred 36.1 million THE tokens into the protocol contract, instantly increasing on-chain supply.
Then, a recursive loop was initiated: deposit THE → borrow other assets → use borrowed assets to buy more THE on-chain → wait for TWAP oracle delay, passive price increase → repeat.
During this process, THE spot price surged from $0.263 to $0.563, more than doubling. About 40 minutes later, the price collapsed to $0.22, triggering a chain of liquidations.
Results: $5.07 million withdrawn, $2.15 million in bad debt
The attacker ultimately borrowed and withdrew:
- 2,172 BNB
- 151,600 CAKE
- 20 BTC
Venus incurred bad debt consisting of approximately 1.18 million CAKE and 1.84 million THE tokens, totaling about $2.15 million. On-chain researchers noted that the attacker’s short positions on THE on centralized exchanges could have yielded additional profits, meaning actual gains might be much higher than the on-chain figures.
This attack technique is a known “supply cap donation attack” — according to CoinTelegraph, this is a known vulnerability that bypasses the supply cap in Compound-fork protocols. As a fork of Compound, Venus inherently has this attack surface.
Venus Emergency Response: 7 markets’ collateral factors set to zero
“Venus is committed to transparency, and a full report will be published after the investigation.” — Venus Protocol official statement
Venus announced that, in addition to previously suspending THE borrowing and withdrawals, it has now set the collateral factors of the following 7 markets to 0 as a precaution against markets with disproportionately high collateral holdings:
- BCH, LTC, UNI, AAVE, FIL, TWT, lisUSD
The protocol emphasizes that all other markets remain unaffected and continue normal operation. A comprehensive post-incident report will be released after the investigation concludes.
This incident highlights the structural risks in DeFi lending protocols when low-liquidity tokens and TWAP oracle delays are combined — if attackers have enough time and capital to slowly build positions, traditional supply cap protections become ineffective.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
Gate Daily Report (April 27): Comments related to the Trump shooting incident boost the TRUMP coin; the U.S. Department of the Treasury will include Venmo in debt-inquiry donation payments
Bitcoin (BTC) sees a sharp short-term surge and rebound, temporarily trading at around $78,900 as of April 27. Trump’s provocative remarks about the shooting incident boosted the prices of meme coins such as TRUMP, MAGA, and DJT, because a carefully crafted narrative has once again come back into view. The U.S. Treasury has moved Venmo into the debt donation payment channel, after the previously strategic Bitcoin reserve bill stalled.
MarketWhisper4h ago
Justin Sun Skips Trump Memecoin Event Amid Legal Dispute with World Liberty
Gate News message, April 26 — Justin Sun, one of the largest investors in the TRUMP token, notably did not attend a memecoin-themed event hosted by US President Donald Trump at Mar-a-Lago in Florida this year, marking a significant shift from his prominent appearance at a similar event last year.
T
GateNews10h ago
Aave, Kelp, LayerZero Propose Releasing $71M in Frozen ETH to Support rsETH Recovery
Gate News message, April 26 — A coalition of major DeFi protocols led by Aave Labs, joined by Kelp DAO, LayerZero, EtherFi, and Compound, filed a Constitutional AIP on Saturday morning asking the Arbitrum DAO to release approximately $71 million in frozen ETH to support DeFi United, a cross-protocol
GateNews15h ago
Litecoin Undergoes Deep Chain Reorganization After MWEB Privacy Layer Zero-Day Exploit
Gate News message, April 26 — Litecoin experienced a deep chain reorganization on Saturday (April 26) after attackers exploited a zero-day vulnerability in its MimbleWimble Extension Block (MWEB) privacy layer, according to the Litecoin Foundation. The reorg spanned blocks 3,095,930 to 3,095,943 and
GateNews17h ago
Aave, Kelp, LayerZero seek Arbitrum release of $71M frozen ETH
Aave Labs, Kelp DAO, LayerZero, EtherFi, and Compound filed a Constitutional AIP on the Arbitrum forum Saturday morning requesting the network's DAO release approximately $71 million in frozen ETH to support rsETH recovery efforts, according to The Block. The proposal seeks release of 30,765.67 ETH
CryptoFrontier04-25 07:07
Gate Daily Report (April 24): US Treasury sanctions Cambodian crypto “pig butchering” scams; Tether mints an additional 1 billion USDT
Bitcoin (BTC) rebound momentum is weakening, with a temporary quote around $78,030 as of April 24. The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned a Cambodian politician linked to a crypto “pig butchering” scam center. Tether issued another 1 billion USDT on the Ethereum network; over the past 5 days, it has issued a total of 3 billion USDT on the Ethereum network.
MarketWhisper04-24 01:55