The post Venus Protocol recovers $13.5M lost in phishing attack appeared on BitcoinEthereumNews.com. Venus Protocol has recovered funds lost in a phishing attack after swift intervention involving a governance vote. Summary A Venus Protocol whale wallet was drained in a phishing attack which led to an estimated $13.5 million loss Venus paused the protocol and used governance powers to liquidate the attacker’s positions. The recovery steadied XVS price, but raised questions about decentralization in crisis management. Venus Protocol, one of the largest lending platforms on BNB (BNB) Chain, has recovered around $13.5 million lost in a phishing incident. The update was shared by the platform on Sept. 3, confirming the assets had been fully restored. Whale wallet compromised On Sept. 2, a high-value Venus user lost control of assets worth around $13.5 million after approving a malicious transaction. Security firms initially estimated losses of up to $27 million, but they later modified these figures to take the user’s debt position into consideration.  Among the stolen assets were wrapped Bitcoin (BTCB), vUSDT, vUSDC, vXRP, and vETH. Notably, this was a user-level compromise rather than a breach of Venus’ smart contracts, demonstrating the ongoing risk of social engineering even in DeFi. Swift response and recovery In order to prevent the attacker from moving funds or closing positions, Venus instantly paused the protocol. The pause stopped the exploiter’s activity and bought time for an emergency governance vote. By approving the forced liquidation of the attacker’s holdings, the community was able to secure the stolen assets before they could be mixed or bridged. Update: Venus Protocol has been fully restored (withdrawals and liquidations resumed) as of 9:58PM UTC. ✅ The lost funds have been recovered under Venus’ protection. ✅ https://t.co/y2uUwPqmtb — Venus Protocol (@VenusProtocol) September 2, 2025 By Sept. 3, security firm PeckShield confirmed that the funds had been restored. Transactions on BNB Chain show the recovery… The post Venus Protocol recovers $13.5M lost in phishing attack appeared on BitcoinEthereumNews.com. Venus Protocol has recovered funds lost in a phishing attack after swift intervention involving a governance vote. Summary A Venus Protocol whale wallet was drained in a phishing attack which led to an estimated $13.5 million loss Venus paused the protocol and used governance powers to liquidate the attacker’s positions. The recovery steadied XVS price, but raised questions about decentralization in crisis management. Venus Protocol, one of the largest lending platforms on BNB (BNB) Chain, has recovered around $13.5 million lost in a phishing incident. The update was shared by the platform on Sept. 3, confirming the assets had been fully restored. Whale wallet compromised On Sept. 2, a high-value Venus user lost control of assets worth around $13.5 million after approving a malicious transaction. Security firms initially estimated losses of up to $27 million, but they later modified these figures to take the user’s debt position into consideration.  Among the stolen assets were wrapped Bitcoin (BTCB), vUSDT, vUSDC, vXRP, and vETH. Notably, this was a user-level compromise rather than a breach of Venus’ smart contracts, demonstrating the ongoing risk of social engineering even in DeFi. Swift response and recovery In order to prevent the attacker from moving funds or closing positions, Venus instantly paused the protocol. The pause stopped the exploiter’s activity and bought time for an emergency governance vote. By approving the forced liquidation of the attacker’s holdings, the community was able to secure the stolen assets before they could be mixed or bridged. Update: Venus Protocol has been fully restored (withdrawals and liquidations resumed) as of 9:58PM UTC. ✅ The lost funds have been recovered under Venus’ protection. ✅ https://t.co/y2uUwPqmtb — Venus Protocol (@VenusProtocol) September 2, 2025 By Sept. 3, security firm PeckShield confirmed that the funds had been restored. Transactions on BNB Chain show the recovery…

Venus Protocol recovers $13.5M lost in phishing attack

2025/09/03 13:57

Venus Protocol has recovered funds lost in a phishing attack after swift intervention involving a governance vote.

Summary

  • A Venus Protocol whale wallet was drained in a phishing attack which led to an estimated $13.5 million loss
  • Venus paused the protocol and used governance powers to liquidate the attacker’s positions.
  • The recovery steadied XVS price, but raised questions about decentralization in crisis management.

Venus Protocol, one of the largest lending platforms on BNB (BNB) Chain, has recovered around $13.5 million lost in a phishing incident. The update was shared by the platform on Sept. 3, confirming the assets had been fully restored.

Whale wallet compromised

On Sept. 2, a high-value Venus user lost control of assets worth around $13.5 million after approving a malicious transaction. Security firms initially estimated losses of up to $27 million, but they later modified these figures to take the user’s debt position into consideration. 

Among the stolen assets were wrapped Bitcoin (BTCB), vUSDT, vUSDC, vXRP, and vETH. Notably, this was a user-level compromise rather than a breach of Venus’ smart contracts, demonstrating the ongoing risk of social engineering even in DeFi.

Swift response and recovery

In order to prevent the attacker from moving funds or closing positions, Venus instantly paused the protocol. The pause stopped the exploiter’s activity and bought time for an emergency governance vote.

By approving the forced liquidation of the attacker’s holdings, the community was able to secure the stolen assets before they could be mixed or bridged.

By Sept. 3, security firm PeckShield confirmed that the funds had been restored. Transactions on BNB Chain show the recovery in action, with assets returned to protocol reserves. Venus announced full resumption of operations at 9:58 PM UTC after completing security checks.

Market and community reaction

XVS, Venus’s governance token, initially dropped nearly 10% on the news, with a surge in trading volume as users rushed to assess the damage. After the recovery efforts were confirmed, the token stabilized, showing renewed confidence. 

The result, which is a rare complete recovery of stolen funds, was made possible by Venus’s emergency tools. However, it has spurred debate about centralization in DeFi because multisig intervention was required to stop the protocol and force liquidations.

Venus said it will release a detailed post-mortem, but emphasized that the protocol itself remained secure.

Phishing attacks have become common in the crypto industry. As opposed to protocol exploits, social engineering relies on user error and avoids code audits, typically through malicious pop-ups or spoof websites. 

Source: https://crypto.news/venus-protocol-recovers-funds-phishing-attack-2025/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

Wormhole launches reserve tying protocol revenue to token

Wormhole launches reserve tying protocol revenue to token

The post Wormhole launches reserve tying protocol revenue to token appeared on BitcoinEthereumNews.com. Wormhole is changing how its W token works by creating a new reserve designed to hold value for the long term. Announced on Wednesday, the Wormhole Reserve will collect onchain and offchain revenues and other value generated across the protocol and its applications (including Portal) and accumulate them into W, locking the tokens within the reserve. The reserve is part of a broader update called W 2.0. Other changes include a 4% targeted base yield for tokenholders who stake and take part in governance. While staking rewards will vary, Wormhole said active users of ecosystem apps can earn boosted yields through features like Portal Earn. The team stressed that no new tokens are being minted; rewards come from existing supply and protocol revenues, keeping the cap fixed at 10 billion. Wormhole is also overhauling its token release schedule. Instead of releasing large amounts of W at once under the old “cliff” model, the network will shift to steady, bi-weekly unlocks starting October 3, 2025. The aim is to avoid sharp periods of selling pressure and create a more predictable environment for investors. Lockups for some groups, including validators and investors, will extend an additional six months, until October 2028. Core contributor tokens remain under longer contractual time locks. Wormhole launched in 2020 as a cross-chain bridge and now connects more than 40 blockchains. The W token powers governance and staking, with a capped supply of 10 billion. By redirecting fees and revenues into the new reserve, Wormhole is betting that its token can maintain value as demand for moving assets and data between chains grows. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/wormhole-launches-reserve
Share
2025/09/18 01:55