T
iTokenly

Volo Protocol hack — April 2026

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 21, 2026
Target typeOther
Loss$3,500,000Price at time of incident
MethodPrivate key compromiseCompromise of a high-privilege vault operator private key. Volo said the key was leaked rather than its audited contracts being flawed; GoPlus Security assessed that the key was most likely obtained through social engineering. The attacker used the key to withdraw from three vaults.
ChainsSui
Audited beforehandYes
OutcomeUsers reimbursed

What happened

On 21 April 2026 an attacker drained three vaults on Volo, a liquid staking and yield protocol on Sui. Volo put the loss at about $3.5m: roughly $2.1m in wrapped bitcoin, about $0.9m in XAUm, MatrixDock's tokenised gold, and about $0.5m in USDC. Roughly $28m of the protocol's remaining total value locked sat in other vaults and was untouched; Volo said it found no shared vulnerability across them.

Volo said the cause was a leaked vault operator private key rather than a defect in its audited contracts. GoPlus Security, Exvul and BitsLab each published on-chain analyses agreeing that a compromised high-privilege operator key was the root cause, with GoPlus assessing that the key was probably obtained through social engineering. Volo did not disclose the specific attack path at the time and said a full post-mortem would follow.

The Slush wallet team spotted the first movements in the XAUm vault. Volo froze all vaults, notified the Sui Foundation and ecosystem partners, and said about $500,000 was frozen within thirty minutes. It also intercepted 19.6 WBTC, worth roughly $2.1m, on the LayerZero bridge before the attacker could move it off Sui.

Recovery continued over the following week. The Sui Foundation helped unlock 100.6 XAUm, and Volo dealt directly with MatrixDock over a further 115 XAUm that were difficult to move because of thin liquidity. In a later update Volo said it had recovered the remaining 64.9 ETH the attacker held, leaving a residual shortfall of about $60,000 that it covered from its own treasury. Its stated position throughout was that it was prepared to absorb the loss rather than pass it to users. No one has been identified.

Sources

  1. VoloPrimary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. Bitcoin.com NewsSecondary · retrieved 2026-08-01
  4. CoinCentralSecondary · retrieved 2026-08-01
  5. CoinAlertNewsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Volo Protocol hack — April 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/volo-protocol
https://itokenly.com/hacks/volo-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.