Tools Crypto Exploit Tracker exploit-0061
Exploit record
Venus
- Loss
- $2M
- Attack vector
- Other
- Chain
- BNB Chain
- Sector
- Borrowing
What happened
On March 16, 2026, Venus Protocol on BSC was left with about $2.18M in bad debt after an attacker abused a supply-cap enforcement gap around THE and then pumped the token in thin liquidity.
This one was slow-cooked, not smash-and-grab. Over roughly nine months, the attacker built a giant uncapped THE position by routing around the normal deposit path and bypassing the intended supply ceiling. Once the position was in place, they started the recursive part: borrow assets, buy THE in low liquidity, push the price higher, transfer more THE into the market, inflate collateral value, repeat. The oracle did what it was told and reflected the manipulated market. When the unwind came, the collateral could not cover the borrowings and Venus was left with bad debt.
On-chain references
- Attacker Wallet 1
0x7a79969a0b9d51d922c4810d2950560360f6f234 - Attacker Wallet 2
0x737bc98f1d34e19539c074b8ad1169d5d45da619 - Attacker Wallet 3
0x1a35bd28efd46cfc46c2136f878777d69ae16231
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
