{"id":95247,"date":"2026-03-16T10:31:33","date_gmt":"2026-03-16T07:31:33","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=95247"},"modified":"2026-03-16T10:35:16","modified_gmt":"2026-03-16T07:35:16","slug":"venus-protocol-loses-2-million-due-to-token-the-manipulation","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/venus-protocol-loses-2-million-due-to-token-the-manipulation\/","title":{"rendered":"Venus Protocol Loses $2 Million Due to Token THE Manipulation"},"content":{"rendered":"<p>On March 15, the lending platform Venus Protocol on BNB Chain was subjected to a hacker attack. The target of the perpetrator was the token THE from the DeFi project Thena.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Our risk manager <a href=\"https:\/\/twitter.com\/AllezLabs?ref_src=twsrc%5Etfw\">@AllezLabs<\/a> shares what we know so far. We will continue to provide updates as our investigation progresses. <a href=\"https:\/\/t.co\/VeBsdzDMXH\">https:\/\/t.co\/VeBsdzDMXH<\/a><\/p>\n<p>\u2014 Venus Protocol (@VenusProtocol) <a href=\"https:\/\/twitter.com\/VenusProtocol\/status\/2033241018704044377?ref_src=twsrc%5Etfw\">March 15, 2026<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The fraudster exploited the low liquidity of THE and executed a classic price <a href=\"https:\/\/forklog.com\/en\/news\/what-is-a-blockchain-oracle\">oracle<\/a> manipulation. He deposited the token as collateral, borrowed other assets against it, immediately purchased additional THE, and repeated the cycle. All actions were precisely synchronized with the moments of the temporary oracle&#8217;s data updates.<\/p>\n<p>This attack vector became possible after Venus added THE to the list of collateral assets in its main pool.<\/p>\n<h2 class=\"wp-block-heading\">Attack Details<\/h2>\n<p>On-chain specialist Weilin Li was among the first to notice the incident. According to him, the hacker artificially raised the coin&#8217;s price from $0.27 to nearly $5.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"zxx\" dir=\"ltr\"><a href=\"https:\/\/t.co\/RV18WHJalA\">https:\/\/t.co\/RV18WHJalA<\/a><\/p>\n<p>\u2014 Weilin (William) Li (@hklst4r) <a href=\"https:\/\/twitter.com\/hklst4r\/status\/2033192855443808515?ref_src=twsrc%5Etfw\">March 15, 2026<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The expert compared the attack to the hack of the DeFi platform Mango Markets, which <a href=\"https:\/\/forklog.com\/en\/news\/hacker-stole-more-than-100-million-from-mango-markets-defi-platform\">occurred in 2022<\/a>.<\/p>\n<p>To bypass the deposit limit on THE in Venus, the perpetrator used a so-called donation attack. He transferred tokens directly to the vTHE smart contract, circumventing the standard minting procedure. This artificially inflated the platform&#8217;s exchange rate and allowed him to bypass the established limit.<\/p>\n<p>After the first round of borrowing, Venus&#8217;s temporary oracle updated THE&#8217;s price to $0.5. This figure significantly lagged behind spot quotes but was almost double the original level.<\/p>\n<p>The attacker attempted to continue the cycle by purchasing more THE with borrowed funds but succumbed to selling pressure. The health factor dropped to nearly one, and the protocol liquidated the position.<\/p>\n<p>The nominal collateral reached $30 million, but there was no market depth for such a sale\u2014THE plummeted into an empty order book. After liquidation, the price fell to $0.24.<\/p>\n<h2 class=\"wp-block-heading\">The Hacker Gained Nothing<\/h2>\n<p>According to Li, the hacker gained virtually nothing and likely even incurred a loss. However, he did not rule out that the perpetrator hedged through perpetual futures on external platforms.<\/p>\n<p>An analyst known as EmberCN estimated Venus&#8217;s irrecoverable debt at $2.15 million\u2014these are unpaid loans amounting to 1.18 million CAKE and 1.84 million THE. He also noted that the attacker&#8217;s initial capital (7400 ETH) came from the mixer <a href=\"https:\/\/forklog.com\/en\/news\/what-is-the-tornado-cash-mixer-and-why-was-it-sanctioned\">Tornado Cash<\/a>.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"zh\" dir=\"ltr\">\u4e00\u4e2a\u4ece Tornado \u6536\u5230 7400 \u679a ETH \u7684\u5730\u5740 (\u9ed1\u5ba2\uff1f)\uff0c\u4e3b\u5bfc\u4e86\u4eca\u5929\u665a\u4e0a CAKE \u548c THE \u7684\u62b5\u62bc\u54c1\u6e05\u7b97\u4e8b\u4ef6\u3002<br \/>\u5bfc\u81f4\u4e86 Venus \u4ea7\u751f\u7ea6 $215 \u4e07\u7684\u6e05\u7b97\u4e8f\u7a7a (118 \u4e07 CAKE+184 \u4e07 THE)\uff0c\u800c\u9ed1\u5ba2\u4ece Venus \u62ff\u5230\u4e86\u7ea6 $507 \u4e07\u8d44\u91d1 (2,172 BNB+151.6 \u4e07 CAKE+20 BTC)\u3002<\/p>\n<p>1\u20e3\u5148\u662f\u901a\u8fc7 0x7a7\u2026234 \u5730\u5740\u4ece Tornado \u6536\u5230 7,400\u2026 <a href=\"https:\/\/t.co\/W6YwQpKJQF\">pic.twitter.com\/W6YwQpKJQF<\/a><\/p>\n<p>\u2014 \u4f59\u70ec (@EmberCN) <a href=\"https:\/\/twitter.com\/EmberCN\/status\/2033204517467308144?ref_src=twsrc%5Etfw\">March 15, 2026<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><em>&#8220;He borrowed 9.92 million USDT to create a commotion, but the assets withdrawn from Venus were worth only $5.07 million. On-chain, the picture is unprofitable, but I suspect he was shorting THE through liquidations and earning on <span data-descr=\"centralized exchanges\" class=\"old_tooltip\">CEX<\/span>,&#8221; the expert noted.<\/em><\/p>\n<p>Back in March 2025, Venus <a href=\"https:\/\/forklog.com\/en\/news\/experts-unveil-details-of-oracle-manipulation-attack-on-venus-protocol\">lost<\/a> over $716,000 due to a similar oracle manipulation attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On March 15, the lending platform Venus Protocol on BNB Chain was subjected to a hacker attack. The target of the perpetrator was the token THE from the DeFi project Thena.<\/p>\n","protected":false},"author":1,"featured_media":95248,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"Venus Protocol lost $2 million due to token manipulation.","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1307,44,1093,1787],"class_list":["post-95247","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-bnb-chain","tag-cybercrime","tag-defi","tag-venus-planet"],"aioseo_notices":[],"amp_enabled":true,"views":"176","promo_type":"1","layout_type":"1","short_excerpt":"Venus Protocol lost $2 million due to token manipulation.","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/95247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=95247"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/95247\/revisions"}],"predecessor-version":[{"id":95249,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/95247\/revisions\/95249"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/95248"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=95247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=95247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=95247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}