Venus Protocol, a lending protocol on BNB Chain, temporarily paused its platform after a large user was phished and tens of millions of dollars of positions tied to their account were drained, but the protocol itself was not hacked. Within roughly half a day, Venus executed an emergency governance process to force-liquidate the attacker’s positions, recovering around $13–13.5 million of the roughly $27 million initially reported as at risk, and then fully restored withdrawals and liquidations. The incident began on September 2, 2025, when a whale user was targeted in a sophisticated phishing/social-engineering attack involving a malicious Zoom client that granted attackers delegated control over the user’s account. By tricking the victim into signing a malicious on‑chain approval transaction, the attacker gained the right to borrow and redeem assets through Venus on the victim’s behalf, draining stablecoins and wrapped assets including vUSDT, vUSDC, wBETH and others. Security firms such as Hexagate, Hypernative, Cyvers, and SlowMist flagged the activity within minutes and later analysis linked the modus operandi to North Korea–associated Lazarus Group operations. In response, Venus Protocol quickly paused the entire platform to prevent further movement of the compromised positions and to verify that neither its smart contracts nor its front end had been breached. An emergency governance vote then authorized the forced liquidation of the attacker’s wallet, sending collateral back under Venus’s control and ultimately to a recovery address, which enabled the project to restore the user’s positions and resume full protocol functionality within about 12–13 hours. The incident is being cited in DeFi circles as a case study in both the risks of wallet-level phishing—where user approvals, not protocol code, are exploited—and the use of protocol governance tools and risk systems to contain and reverse damage when a single large account is compromised.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Phishing

Comments