Venus Protocol Core Pool (THE market) hack — March 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 15, 2026 |
| Target type | Lending protocol |
| Loss | $2,150,000Published estimates range $2,150,000 to $3,700,000Price at time of incident |
| Method | Contract logic errorA donation attack on the vTHE market. The vToken contract's getCashPrior function reads the contract's raw token balance rather than internally tracked supply, so transferring THE directly to vTHE inflated the vTHE/THE exchange rate without passing the mintAllowed() supply-cap check. The attacker then looped borrow, buy THE, donate THE, using the resulting inflated collateral value, aided by thin THE liquidity that let the oracle price be pushed upward. |
| Chains | BNB Chain |
| Audited beforehand | Code4rena (2023 contest, per Venus governance discussion) |
| Outcome | Unresolved |
What happened
The THE (Thena) market in Venus Protocol's core pool on BNB Chain was attacked on 15 March 2026 at about 11:55 UTC. Venus's post-mortem describes a donation attack: because the vToken contract's getCashPrior function reads the underlying token balance directly rather than internally tracked supply, and supply caps are enforced only in mintAllowed, an attacker who transfers THE directly to the vTHE contract inflates the vTHE/THE exchange rate without passing the cap check. The attacker, who had accumulated roughly 84% of the 14.5 million THE supply cap over the preceding nine months, repeatedly borrowed against the inflated collateral, bought more THE on the market and donated it back. The exchange rate rose 3.81x (10,086,934,836 to 38,420,106,438) and THE supplied reached 53,230,145, 367% of the cap. THE's thin liquidity allowed its price to be driven from about $0.26 toward $4 on the Binance Oracle before collapsing to roughly $0.22.
The published figures measure different things. Venus's own accounting, repeated in its governance patch proposal, is approximately $2.15 million of bad debt left on the protocol, held in about 1.18 million CAKE and 1.84 million THE; Halborn gives approximately $2.18 million for the same item. Reporting by Wu Blockchain puts the assets extracted at about $3.7 million. BlockSec calculates that the attacker borrowed roughly $14.9 million at peak, that 254 liquidation callers processed 8,048 transactions against the position, and that the attack was unprofitable on-chain — the attacker invested $9.92 million and retained about $5.2 million.
Venus froze THE borrowing and withdrawals, applied a zero collateral factor to eight further markets as a precaution, and advanced VIPs 600, 601 and 602 to replace balanceOf-based cash reporting with an internalCash variable tracked by the protocol's own _doTransferIn, _doTransferOut and badDebtRecovered functions, covering BNB Chain plus Arbitrum One, Base, Ethereum, opBNB, OP Mainnet, Unichain and zkSync. Venus states the vulnerability class is a known weakness in Compound forks and had been identified in a prior Code4rena audit of Venus; Halborn reports the protocol had treated donations as an intentional feature and declined to fix it. No reimbursement has been announced.
Sources
- Venus Protocol governancePrimary · retrieved 2026-08-01
- Venus Protocol governancePrimary · retrieved 2026-08-01
- BlockSecSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- The Cryptonomist (citing Wu Blockchain)Secondary · retrieved 2026-08-01
Official post-mortem: https://community.venus.io/t/the-market-incident-post-mortem/5712
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Venus Protocol Core Pool (THE market) hack — March 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/venus-core-poolhttps://itokenly.com/hacks/venus-core-poolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.