On September 2, 2025, Venus Protocol experienced a serious phishing incident, in which a single user lost approximately $13 million. This attack forced the platform to pause its core activities until the investigation was complete.
Circumstances of the Attack
According to reports from Venus Protocol on X, the attack began when the victim unknowingly approved a phishing request. This gave the attacker control over their wallet without needing access to private keys, allowing them to directly redeem and borrow assets. Specifically, the attacker initiated a flash loan of 285.72 BTCB to settle the victim’s debt of 306.89 BTCB. Once that was handled, they exploited a phishing approval to siphon the victim’s deposits into their own wallet. The haul included $19.8 million in USDT, 3,744 wBETH, 311,571 FDUSD, and over 15,000 USDC. Additionally, the attacker borrowed another $7.14 million in USDC, putting the victim’s BNB up as collateral, which caused a partial liquidation of around $2.66 million.
Security Measures
Venus Protocol stated that security firms Hexagate, Hypernative, and Peckshield alerted them about the suspicious activity. As a consequence, Venus halted its procedures and ceased important activities, preventing the stolen assets from being transferred any further. The protocol also created a Telegram group for coordinated response efforts that included representatives from Peckshield, Venus, and the victim. Venus then began a thorough review of its frontend to ensure that no official dApp was compromised.
Recovery and Restoration
Furthermore, Venus quickly developed a custom recovery tool to retrieve the stolen assets. This tool captured the stolen tokens, paid off the attacker’s debt, and safely moved everything into a secure wallet. Venus locked down all collateral and fully liquidated the attacker’s wallet using borrowed funds. The team was able to retrieve the stolen funds and restore the platform to normal functioning in under 13 hours. This incident emphasizes the need for rapid response and coordinated defense in DeFi, highlighting phishing as one of the greatest threats rather than an issue with the protocol itself.
The phishing attack on Venus Protocol serves as a crucial reminder of the risks in DeFi and demonstrates how quick response can help minimize the impact of cyberattacks.