Decentralized lending platform Venus Protocol is investigating a suspected exploit that may have drained more than $3.7 million in digital assets from its Core Decentralized lending platform Venus Protocol is investigating a suspected exploit that may have drained more than $3.7 million in digital assets from its Core

Venus Protocol Hit by Suspected $3.7M Exploit After Supply Cap Manipulation

2026/03/16 01:54
6 min read
For feedback or concerns regarding this content, please contact us at [email protected]

Decentralized lending platform Venus Protocol is investigating a suspected exploit that may have drained more than $3.7 million in digital assets from its Core Pool on BNB Chain.

The incident came to light after on-chain data flagged unusual borrowing activity tied to a wallet identified as 0x1a35…6231. The address managed to extract a combination of assets, including roughly 20 BTC, 1.5 million CAKE, and about 200 BNB, after leveraging a large position in THE tokens as collateral.

According to early analysis, the attacker used the collateral to borrow several assets from the protocol, including CAKE, BTCB, and BNB. The total value of the borrowed assets exceeded $3.7 million before liquidation events began.

At the time of writing, tens of millions of THE tokens that were used as collateral are being liquidated, suggesting that the protocol’s risk mechanisms have already kicked in.

The Venus team acknowledged the situation and confirmed that several precautionary steps have already been taken while the investigation continues.

Attack Targets Supply Cap Controls

The exploit appears to revolve around a supply cap manipulation involving the THE token market inside the Venus Core Pool.

Supply caps are designed to limit how much of a particular asset can be used within a lending market. They act as a safeguard to prevent excessive exposure to a single token.

In this case, however, the attacker managed to bypass that restriction.

As a precaution, Venus has paused borrowing and withdrawals for THE. The team also halted activity in several markets where liquidity concentration could pose additional risk.

The paused markets include:

  •  BCH
  •  LTC
  •  UNI
  •  AAVE
  •  FIL
  •  TWT

Despite the disruption, Venus clarified that most other markets on the protocol remain fully operational.

Security researchers tracking the incident believe the exploit was not spontaneous. Instead, it appears to have been planned and executed in multiple stages over several months.

Months of Quiet Accumulation

One of the more striking details of the exploit is how long the preparation phase appears to have lasted.

On-chain data suggests the attacker began accumulating THE tokens as far back as June 2025.

Rather than making large purchases all at once, the wallet gradually built its position over the course of nine months. By the time the attack unfolded, the address had accumulated around 84% of the token’s supply cap on Venus, which stood at 14.5 million THE.

At 11:00 UTC on the day of the exploit, the wallet had already supplied 12.2 million THE to the protocol, comfortably within the allowed limit.

Nothing about the position appeared unusual at that point, which may explain why the activity went largely unnoticed until later.

The real breakthrough came when the attacker found a way to expand that position far beyond the cap.

Bypassing the Supply Cap

Instead of using the standard deposit process, the attacker transferred tokens directly to the Venus protocol contract.

By doing so, they managed to bypass the system that normally enforces supply caps.

This allowed the wallet to dramatically increase its collateral position in a very short period.

The timeline shows just how quickly things escalated:

  •  11:00 UTC: 12.2 million THE supplied (within the cap)
  •  12:00 UTC: 49.5 million THE supplied (over 3x the cap)
  •  12:42 UTC: 53.2 million THE supplied

By 12:42 UTC, the attacker had built a massive collateral position totaling 53.2 million THE tokens, about 3.67 times the protocol’s intended cap.

With such a large collateral base in place, the attacker could begin borrowing assets from the platform.

Recursive Borrowing Pushes THE Price Higher

After establishing the oversized collateral position, the attacker moved to the next stage, manipulating the token’s price through a recursive borrowing loop.

The strategy followed a repeating cycle:

Deposit THE → Borrow assets → Purchase more THE → Wait for oracle update → Increase collateral value → Repeat

Because THE had relatively low on-chain liquidity, even moderate purchases had a noticeable impact on its price.

As the loop continued, the token’s oracle price rose sharply. Data shows the price moved from around $0.27 to nearly $0.53 during the attack.

This artificial price increase boosted the value of the attacker’s collateral, which in turn allowed them to borrow even larger amounts from the protocol.

Once the manipulation ended and liquidations began, however, the price quickly reversed, falling to roughly $0.24.

Borrowed Assets Reach Millions

At the peak of the exploit, recorded at block 86738236 around 12:42 UTC, the attacker’s position had grown substantially.

The wallet had supplied 53.2 million THE tokens as collateral.

Against that collateral, the attacker borrowed multiple assets from Venus, including:

  •  6.67 million CAKE
  •  2,801 BNB
  •  1.97K WBNB
  •  1.58 million USDC
  •  20 BTCB

Investigators also identified a second related address (0x737b) that played a role in the operation.

That wallet had earlier deposited 1.58 million USDC as collateral and borrowed 4.63 million THE tokens in the same transaction that initiated the main attack at 11:55 UTC.

Liquidations for this secondary position began shortly afterward, starting around 12:04 UTC.

Venus Responds as Investigation Continues

Following the discovery of the exploit, the Venus team moved quickly to limit potential damage.

The protocol paused the THE market along with several other at-risk markets, while confirming that most of the platform remains unaffected.

Developers say they are now working closely with security partners and researchers to fully understand what happened.

The team has also promised to release a detailed post-mortem report once the investigation is complete.

According to the protocol, the upcoming report will likely include technical fixes and security improvements, particularly around oracle mechanisms and supply cap enforcement.

While incidents like this are not new in decentralized finance, they highlight the challenges protocols face when trying to balance open access with strong risk controls.

For now, the focus remains on stabilizing the affected markets and preventing similar exploits in the future.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.

Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news!

Market Opportunity
Capverse Logo
Capverse Price(CAP)
$0.09645
$0.09645$0.09645
+1.90%
USD
Capverse (CAP) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
Shiba Inu’s 1,549% Spike: Can Bulls Take Control Again And Trigger An Explosive Rally?

Shiba Inu’s 1,549% Spike: Can Bulls Take Control Again And Trigger An Explosive Rally?

Shiba Inu (SHIB) has experienced a sudden increase in futures net flows, skyrocketing more than 1,549% in one day. The spike comes amid broader market volatility
Share
NewsBTC2026/03/17 04:30
US Stocks Surge Higher: Major Indices Post Significant Gains in Bullish Trading Session

US Stocks Surge Higher: Major Indices Post Significant Gains in Bullish Trading Session

BitcoinWorld US Stocks Surge Higher: Major Indices Post Significant Gains in Bullish Trading Session Major US stock indices closed substantially higher today,
Share
bitcoinworld2026/03/17 04:30