Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Venus Protocol restores services, recovers funds stolen after $27M exploit

Venus Protocol restores services, recovers funds stolen after $27M exploit

CryptopolitanCryptopolitan2025/09/03 13:25
By:By Florence Muchai

Share link:In this post: Venus Protocol fully restored services and recovered $27 million after halting withdrawals and liquidations due to a phishing-related exploit. The community approved an emergency plan, allowing staged recovery, security checks, and the resumption of operations within 24 hours. Experts warn that phishing scams remain a top DeFi threat, exploiting user trust through fake websites during events like airdrops and token launches.

BNB Chain lending platform Venus Protocol resumed full operations after an exploit on Tuesday forced an emergency vote to suspend withdrawals and liquidations. The platform confirmed later that it had restored services and recovered the $27 million worth of digital assets compromised in the incident.

The disruption began when Venus identified suspicious activity linked to a phishing scam, which was also flagged by several cybersecurity firms. As reported by Cryptopolitan, blockchain analysts had mentioned irregular transactions in the platform’s Core Pool Comptroller contract, which routes user assets vUSDC and vETH.

Venus called for an emergency vote to pause services in order to limit losses and allow security teams to assess whether the exploit compromised Venus’ infrastructure. 

Although users were unable to withdraw or liquidate positions during the hiatus, the protocol partially restored some functionality later the same day for them to repay debt and supply funds, actions that helped them protect their positions until normal operations could resume.

Venus Protocol’s proposed plan for restoration approved

Venus Protocol proposed a plan to its community to determine the immediate steps for handling the crisis. The four-stage plan was outlined as follows: partial restoration within five hours, recovery of stolen funds within seven hours, a full security review within 24 hours, and the eventual resumption of all services once checks were completed.

See also World Liberty Financial wants to expand its USD1 stablecoin to Solana

Voting ended at around 5 PM UTC, with the community voting “100% to proceed,” the protocol announced. “We are so thankful for your support, and will proceed with the execution,” the team wrote on X.

By 9:58 PM UTC, Venus confirmed that the plan had been completed successfully. 

“Venus Protocol has been fully restored, withdrawals and liquidations resumed. The lost funds have been recovered under Venus’ protection,” the platform said.

The exploit stemmed from a phishing incident that tricked a Venus user into approving a malicious transaction, which granted an attacker access to the user’s $27 million worth of digital assets. 

Phishing scams imitate trusted platforms with near-identical websites made to lure users into entering credentials or approving harmful transactions.

According to Cyvers, a blockchain security firm, this particular attack was launched using a domain closely resembling a legitimate site. The small differences are, more often than not unnoticed when victims rush through approvals for token launches or airdrops. Once the user approved the transaction, their wallet was drained.

Venus explained that its quick response prevented the attacker from moving the stolen assets out of their wallet. 

See also Trump says court got it wrong after emergency tariffs ruled illegal

“Fortunately, the suspicious transaction was identified almost immediately, and Venus Protocol was paused. Because of this quick response, the stolen funds remain locked in the attacker’s wallet and this is why Venus is currently paused,” the platform wrote in its emergency update.

Venus to publish full post-mortem after analysis

Venus Protocol said it would publish a full post-mortem of the incident once investigations are complete. The platform also thanked its users for their trust and patience during the suspension of services. 

“Hackers have no place on Venus. Thank you for your patience, understanding, and continued trust as we work tirelessly to protect our users, safeguard our community, and uphold the integrity of the Venus Protocol. The community is the foundation of Venus, and we will always act in your best interest,” the team stated.

Phishing attacks are still atop of the most common threats in decentralized finance, accounting for almost 20% of the $2.17 billion stolen from crypto services in 2025, according to Chainalysis’ mid-year report.

If you're reading this, you’re already ahead. Stay there with our newsletter .

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Phishing Risks in DeFi: What Investors Must Do to Protect Their Assets

- DeFi phishing attacks now account for 56.5% of breaches in 2025, surpassing technical exploits as the sector's top security threat. - 2025 phishing losses exceeded $410M, with AI-generated scams achieving 54% click-through rates and triggering market instability like the Venus Protocol $13.5M incident. - Investors must adopt institutional custody solutions, prioritize user education, and demand governance upgrades to combat phishing risks undermining DeFi's trustless model. - Cybercriminals increasingly

ainvest2025/09/03 20:35
Phishing Risks in DeFi: What Investors Must Do to Protect Their Assets

Is Bitcoin’s ETF-Driven Growth Sustainable Amid Shifting Institutional Demand?

- -2025 institutional crypto demand shows Bitcoin ETFs rebounding with $33.6B holdings, while Ethereum ETFs face volatile inflows/outflows. - -Bitcoin's zero-yield model contrasts with Ethereum's 6% staking returns under the CLARITY Act, driving dual-asset allocation strategies. - -Ethereum's deflationary tokenomics and regulatory clarity attract 59% of institutions planning >5% crypto allocations in 2025. - -Solana/XRP ETFs gain traction with $311M combined inflows, reflecting diversification into high-gr

ainvest2025/09/03 20:35
Is Bitcoin’s ETF-Driven Growth Sustainable Amid Shifting Institutional Demand?

MoonBull ($MOBU): The Whitelist-Driven Meme Coin 2.0 with 1000x Potential

- MoonBull ($MOBU) redefines meme coins with structured incentives, Ethereum-based scalability, and institutional-grade security, positioning as a 1000x opportunity in 2025. - Its tokenomics allocate 30% to liquidity pools, 20% for 66-80% APY staking rewards, and 2% auto-burn per transaction, creating a self-sustaining flywheel effect. - Leveraging Ethereum Layer 2 infrastructure (Arbitrum/Base), MoonBull achieves 10,000 TPS and 53% lower gas fees, enabling seamless DeFi integration and institutional credi

ainvest2025/09/03 20:35
MoonBull ($MOBU): The Whitelist-Driven Meme Coin 2.0 with 1000x Potential

Ethereum's Institutional Adoption: A Strategic Asset in Web3 Expansion

- Ethereum's 4.5–5.2% staking yields and 2025 SEC reclassification as a utility token drove $9.4B ETF inflows and 29.6% supply staked by institutions. - 53.14% of $26.63B RWA tokenization market relies on Ethereum, with BlackRock and Goldman Sachs tokenizing $10.8B U.S. Treasuries and $8.32B gold. - DeFi TVL surged to $223B in 2025 via L2 scalability, enabling institutional yield generation through tokenized RWAs and programmable finance. - Regulatory clarity under GENIUS Act and Ethereum's deflationary su

ainvest2025/09/03 20:35
Ethereum's Institutional Adoption: A Strategic Asset in Web3 Expansion