Share this article

BNB Chain-Based Venus Protocol Drained of $27M on Suspected Contract Compromise

The attack involved updating a contract to a malicious address, affecting tokens like vUSDC and vETH.

Updated Sep 2, 2025, 9:55 a.m. Published Sep 2, 2025, 9:47 a.m.
Hacker sitting in a room
(Clint Patterson/Unsplash)

What to know:

  • Venus Protocol was exploited, losing an estimated $27 million in assets.
  • The attack involved updating a contract to a malicious address, affecting tokens like vUSDC and vETH.
  • Security teams are monitoring the situation, and the Venus community has not yet released an official statement.

Venus Protocol, one of the largest lending platforms on the BNB Chain, was hit by a suspected exploit on Tuesday with attackers seemingly draining an estimated $27 million worth of assets.

On-chain sleuths said they suspect the protocol’s Core Pool Comptroller contract was updated to a malicious address, which then siphoned off tokens including vUSDC and vETH.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

Security teams are tracking the stolen assets and the Venus community has yet to issue an official statement.

The funds remain in the attacker’s contract and have not yet been swapped, leaving open questions about whether the exploit will evolve into a full-scale cash-out.

Venus functions as a money market on the BNB Chain, allowing users to deposit assets such as stablecoins and major tokens to earn interest, while borrowers post collateral to take out loans.

Its native token, XVS, plays a role in governance and protocol incentives. At its peak, Venus held over $7 billion in assets, making it a core part of BNB Chain’s DeFi ecosystem.

(This is a developing story.)

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

ZKsync Lite to Shut Down in 2026 as Matter Labs Moves On

Sunset in San Salvador. Credit: Ricky Mejia, Unsplash

The company framed the move, happening in early 2026, as a planned sunset.

What to know:

  • Matter Labs plans to deprecate ZKsync Lite, the first iteration of its Ethereum layer-2 network, the team said in a post on X over the weekend.
  • The company framed the move, happening in early 2026, as a planned sunset for an early proof-of-concept that helped validate their zero-knowledge rollup design choices before newer systems went live.