YFarmX

Tools Crypto Exploit Tracker exploit-0061

Exploit record

Venus

Loss
$2M
Attack vector
Other
Chain
BNB Chain
Sector
Borrowing

What happened

On March 16, 2026, Venus Protocol on BSC was left with about $2.18M in bad debt after an attacker abused a supply-cap enforcement gap around THE and then pumped the token in thin liquidity.

This one was slow-cooked, not smash-and-grab. Over roughly nine months, the attacker built a giant uncapped THE position by routing around the normal deposit path and bypassing the intended supply ceiling. Once the position was in place, they started the recursive part: borrow assets, buy THE in low liquidity, push the price higher, transfer more THE into the market, inflate collateral value, repeat. The oracle did what it was told and reflected the manipulated market. When the unwind came, the collateral could not cover the borrowings and Venus was left with bad debt.

On-chain references

  • Attacker Wallet 10x7a79969a0b9d51d922c4810d2950560360f6f234
  • Attacker Wallet 20x737bc98f1d34e19539c074b8ad1169d5d45da619
  • Attacker Wallet 30x1a35bd28efd46cfc46c2136f878777d69ae16231

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026