T
iTokenly

Venus Protocol Core Pool (THE market) hack — March 2026

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 15, 2026
Target typeLending protocol
Loss$2,150,000Published estimates range $2,150,000 to $3,700,000Price at time of incident
MethodContract logic errorA donation attack on the vTHE market. The vToken contract's getCashPrior function reads the contract's raw token balance rather than internally tracked supply, so transferring THE directly to vTHE inflated the vTHE/THE exchange rate without passing the mintAllowed() supply-cap check. The attacker then looped borrow, buy THE, donate THE, using the resulting inflated collateral value, aided by thin THE liquidity that let the oracle price be pushed upward.
ChainsBNB Chain
Audited beforehandCode4rena (2023 contest, per Venus governance discussion)
OutcomeUnresolved

What happened

The THE (Thena) market in Venus Protocol's core pool on BNB Chain was attacked on 15 March 2026 at about 11:55 UTC. Venus's post-mortem describes a donation attack: because the vToken contract's getCashPrior function reads the underlying token balance directly rather than internally tracked supply, and supply caps are enforced only in mintAllowed, an attacker who transfers THE directly to the vTHE contract inflates the vTHE/THE exchange rate without passing the cap check. The attacker, who had accumulated roughly 84% of the 14.5 million THE supply cap over the preceding nine months, repeatedly borrowed against the inflated collateral, bought more THE on the market and donated it back. The exchange rate rose 3.81x (10,086,934,836 to 38,420,106,438) and THE supplied reached 53,230,145, 367% of the cap. THE's thin liquidity allowed its price to be driven from about $0.26 toward $4 on the Binance Oracle before collapsing to roughly $0.22.

The published figures measure different things. Venus's own accounting, repeated in its governance patch proposal, is approximately $2.15 million of bad debt left on the protocol, held in about 1.18 million CAKE and 1.84 million THE; Halborn gives approximately $2.18 million for the same item. Reporting by Wu Blockchain puts the assets extracted at about $3.7 million. BlockSec calculates that the attacker borrowed roughly $14.9 million at peak, that 254 liquidation callers processed 8,048 transactions against the position, and that the attack was unprofitable on-chain — the attacker invested $9.92 million and retained about $5.2 million.

Venus froze THE borrowing and withdrawals, applied a zero collateral factor to eight further markets as a precaution, and advanced VIPs 600, 601 and 602 to replace balanceOf-based cash reporting with an internalCash variable tracked by the protocol's own _doTransferIn, _doTransferOut and badDebtRecovered functions, covering BNB Chain plus Arbitrum One, Base, Ethereum, opBNB, OP Mainnet, Unichain and zkSync. Venus states the vulnerability class is a known weakness in Compound forks and had been identified in a prior Code4rena audit of Venus; Halborn reports the protocol had treated donations as an intentional feature and declined to fix it. No reimbursement has been announced.

Sources

  1. Venus Protocol governancePrimary · retrieved 2026-08-01
  2. Venus Protocol governancePrimary · retrieved 2026-08-01
  3. BlockSecSecondary · retrieved 2026-08-01
  4. HalbornSecondary · retrieved 2026-08-01
  5. The Cryptonomist (citing Wu Blockchain)Secondary · retrieved 2026-08-01

Official post-mortem: https://community.venus.io/t/the-market-incident-post-mortem/5712

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Venus Protocol Core Pool (THE market) hack — March 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/venus-core-pool
https://itokenly.com/hacks/venus-core-pool

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.