Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Sichere ProgrammierungI built a sell planner to dodge the pros. They were under 4% of buys(25.09.2026 um 04:26 Uhr)
•
Sichere ProgrammierungNansen called Binance 14 a 'Token Billionaire'. The name cost 1 credit(25.09.2026 um 04:26 Uhr)
•
Sichere Programmierung50,000 property tests passed while my app crowned an impostor(25.09.2026 um 04:26 Uhr)
•
Sichere ProgrammierungI made a small website to check Codex reset(25.09.2026 um 04:28 Uhr)
•
Sichere ProgrammierungAI Is My Workforce, Not My Replacement(25.09.2026 um 04:30 Uhr)
•
AI & KI NachrichtenThe Machine Learning Career Roadmap I'd Follow If I Started Today(25.09.2026 um 04:30 Uhr)
•••
Sichere ProgrammierungNormalize Units at the Boundary, or Ship a 12x Bug(25.09.2026 um 04:39 Uhr)
•
Sichere ProgrammierungA No-Repeat Random Draw Looks Trivial Until Round 70(25.09.2026 um 04:40 Uhr)
•
Sichere ProgrammierungI built a sell planner to dodge the pros. They were under 4% of buys(25.09.2026 um 04:26 Uhr)
•
Sichere ProgrammierungNansen called Binance 14 a 'Token Billionaire'. The name cost 1 credit(25.09.2026 um 04:26 Uhr)
•
Sichere Programmierung50,000 property tests passed while my app crowned an impostor(25.09.2026 um 04:26 Uhr)
•
Sichere ProgrammierungI made a small website to check Codex reset(25.09.2026 um 04:28 Uhr)
•
Sichere ProgrammierungAI Is My Workforce, Not My Replacement(25.09.2026 um 04:30 Uhr)
•
AI & KI NachrichtenThe Machine Learning Career Roadmap I'd Follow If I Started Today(25.09.2026 um 04:30 Uhr)
•••
Sichere ProgrammierungNormalize Units at the Boundary, or Ship a 12x Bug(25.09.2026 um 04:39 Uhr)
•
Sichere ProgrammierungA No-Repeat Random Draw Looks Trivial Until Round 70(25.09.2026 um 04:40 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

The Venus Protocol Donation Attack: How a Dismissed Audit Finding Became a $2.15M Bad Debt — Twice

On March 15, 2026, Venus Protocol on BNB Chain was hit by an exploit that left it with $2.15 million in bad debt. The attack targeted the THENA (THE) token market using a donation attack — a vulnerability class so well-known it was l…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

On March 15, 2026, Venus Protocol on BNB Chain was hit by an exploit that left it with $2.15 million in bad debt. The attack targeted the THENA (THE) token market using a donation attack — a vulnerability class so well-known it was literally flagged in Venus's own Code4rena audit.



The protocol dismissed the finding. Then it got exploited. Again.



Here's the anatomy of what went wrong, why three separate lines of defense failed simultaneously, and what every Compound-fork lending protocol needs to learn from this.









The Vulnerability: Donation Attacks in Compound Forks



In Compound-style lending protocols, supply caps limit how much of a given token can be deposited as collateral. But here's the critical design flaw: most implementations only enforce this cap on the mint path — the standard deposit function that issues vTokens (or cTokens).



They don't account for tokens transferred directly to the contract address.




// The mint path checks the supply cap
function mintInternal(uint mintAmount) internal {
require(totalSupply + mintAmount <= supplyCap, "supply cap exceeded");
// ... mint vTokens
}

// But a direct ERC-20 transfer bypasses everything:
// IERC20(THE).transfer(address(vTHE), amount);
// No cap check. No access control. Just... more tokens.






When tokens are sent directly to the vToken contract, the contract's underlying balance increases without minting new vTokens. Since the exchangeRate is calculated as:




exchangeRate = (underlyingBalance + totalBorrows - reserves) / totalSupply






This inflates the exchange rate. Every existing vToken holder suddenly has more borrowing power — without any supply cap check firing.






The 9-Month Setup



This wasn't a flash loan one-block wonder. The attacker started in June 2025:





  1. Funded via Tornado Cash: 7,447 ETH → deposited into Aave as collateral → borrowed $9.92M in stablecoins


  2. Gradual accumulation: Over 9 months, systematically bought THE tokens across multiple wallets


  3. Reached 84% of supply cap: By March 15, the attacker controlled ~12.2M THE out of the 14.5M cap



Every single one of these transactions was visible on-chain. The address had even been flagged by community members. Venus declined to act, citing decentralization.






The Execution



On March 15, 2026 at 11:00 UTC, the attacker deployed a malicious contract and executed the donation attack:





  1. Donated THE directly to the vTHE contract, bypassing the supply cap


  2. Exchange rate inflated 3.81x, massively increasing borrowing power


  3. Borrowed ~$14.9M in BTCB, CAKE, USDC, and BNB against the inflated collateral


  4. Repeated the cycle: borrowed → swapped for THE → donated → borrowed more


  5. THE price pushed from $0.263 to over $0.51 during the manipulation


  6. Total THE in Venus reached 53.23M — that's 367% of the 14.5M supply cap






Three Lines of Defense, Three Failures






1. Supply Cap (Bypassed)



The supply cap only guarded the mint function. Direct transfers went unchecked. This is the core vulnerability.



Fix: Supply caps must account for the contract's actual underlying balance, not just minted supply. The getCashPrior() function reads the raw token balance — any discrepancy between this and the tracked supply should trigger circuit breakers.






2. Oracle-Based Collateral Valuation (Manipulated)



The attacker's buy-and-donate cycle artificially inflated THE's market price alongside the exchange rate manipulation. The oracle faithfully reported the manipulated price.



Fix: TWAP oracles with longer windows, circuit breakers on rapid price movements, and collateral factor adjustments based on on-chain liquidity depth.






3. Liquidation Market (Overwhelmed)



254 liquidation bots competed across 8,048 transactions to unwind the position. Despite this aggressive competition, $2.15M in bad debt remained. The THE token's price collapsed from $0.51 to $0.22 during the liquidation cascade — below its pre-attack level — making each successive liquidation less effective.



Fix: Gradual liquidation mechanisms (like Aave's soft liquidation), protocol-owned liquidation reserves, and dynamic liquidation incentives that scale with position risk.






The Audit Finding That Was Dismissed



This is the most damning part. The donation attack vector was explicitly identified during Venus Protocol's Code4rena security audit. The Venus team's response:




"Donations are an intentional feature with no negative side effects."




This wasn't ignorance. It was a conscious decision to accept risk that the team didn't fully understand.



And it wasn't even the first time. In February 2025, Venus suffered the same class of attack on its zkSync deployment, resulting in $700K+ in bad debt. The protocol saw the same vulnerability exploited, patched the specific instance, and still didn't address the systemic issue across all deployments.






Detection Opportunities That Were Missed



The 9-month preparation window provided multiple detection signals:





  • Single entity accumulating 84% of supply cap — visible from June 2025 onwards via position concentration monitoring


  • Tornado Cash-funded address active in protocol — visible from June 2025 via funding source analysis


  • Community flagging of suspicious address — months before exploit via governance alerts


  • Rapid position changes on attack day — March 15, 11:00 UTC via real-time transaction monitoring



None of these required sophisticated tooling. Basic position concentration alerts — "notify when any address holds >50% of a market's supply" — would have surfaced this months in advance.






Takeaways for Builders and Auditors






If You're Building a Compound Fork





  1. Validate supply against actual balance, not just mint accounting. Add invariant checks:




require(
IERC20(underlying).balanceOf(address(this)) <= expectedBalance + DUST_THRESHOLD,
"unexpected balance increase"
);







  1. Don't dismiss audit findings because the behavior is "intentional." Intent doesn't equal safety.


  2. Monitor position concentration as a first-class risk metric, not an afterthought.


  3. Implement exchange rate change limits — if the rate jumps >X% in a single block, pause the market.







If You're Auditing




  1. Test the full deposit surface, not just the intended entry points. Direct transfers, transferFrom with pre-approved amounts, and callback-based deposits should all be validated.


  2. Challenge "won't fix" responses with concrete attack scenarios. "This is intended behavior" is not a security argument.


  3. Check for repeat vulnerabilities across different deployments of the same protocol. If it happened on zkSync, it can happen on BNB Chain.







If You're Running a Lending Protocol




  1. Position concentration is a leading indicator. A single address at 84% of your supply cap is a red flag, not a feature.


  2. Historical exploits on your own protocol are the highest-signal intelligence you have. Venus ignored its own zkSync incident. Don't repeat this pattern.


  3. Liquidation markets have limits. 254 competing bots still couldn't prevent $2.15M in bad debt. Design for liquidation failure, not just liquidation success.










Timeline





  • June 2025 — Attacker begins accumulating THE via Tornado Cash funding


  • Feb 2025 — Venus zkSync deployment suffers similar donation attack ($700K+ bad debt)


  • Pre-attack — Community flags suspicious address; Venus declines action


  • Mar 15, 2026 11:00 UTC — Attacker deploys malicious contract, begins donation attack


  • Mar 15, 2026 ~12:00 UTC — 8,048 liquidation transactions begin unwinding the position


  • Post-attack — Venus suspends THE lending/borrowing, sets collateral factor to zero






The Venus incident is a masterclass in how DeFi protocols fail: not because the vulnerability was unknown, but because the warning was ignored. The audit found it. The community flagged it. A previous exploit demonstrated it. And still, three lines of defense crumbled against an attacker who took nine months to prepare.



The lesson isn't "get better audits." It's listen to the audits you already have.






References: Venus Post-Mortem, BlockSec Analysis, Halborn Writeup

1. Sofort-Triage & Abwehrmaßnahmen

SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - The Venus Protocol Donation Attack: How a Dismissed Audit Finding Became a $2.15M Bad Debt — Twice
id: d824b2bf-794a-4c60-87ce-9a9edeb8e11f
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-25"
        description = "YARA Signature for "
    strings:
        $str = "The Venus Protocol Donation At" ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("The Venus Protocol Donation Attack How a")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*The Venus Protocol Donation Attack How a*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "The Venus Protocol Donation Attack How a"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich The Venus Protocol Donation Attack: How .... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten The Venus Protocol Donation Attack: How a Dismissed Audit Finding Became a $2.15M Bad Debt — Twice

Thematisch verwandte Begriffe: Venus, Protocol, Donation, Attack · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-87722 | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search q…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...
↗ Original-Quelle