The post How A Venus Protocol Trader Lost $30 Million appeared on BitcoinEthereumNews.com. A dramatic incident on Venus Protocol has resulted in the loss of nearly $30 million worth of assets. While many initially suspected a hack, blockchain security analysts at Cyvers confirmed to BeInCrypto that this was a user-side mistake, not a vulnerability in the protocol itself. Phishing Scam Costs Venus Protocol User $30 Million, Not a Protocol Hack PeckShield first flagged the suspicious activity, noting that a Venus Protocol user had been drained of approximately $27 million after falling victim to a phishing scam. The attacker gained access by tricking the victim into approving a malicious transaction, which gave unlimited permissions to transfer assets from the wallet. The stolen tokens included around $19.8 million in vUSDT, $7.15 million in vUSDC, $146,000 in vXRP, $22,000 in vETH, and even 285 BTCB, representing what observers described as “generational wealth.” Defi analyst Ignas also weighed in, noting that Venus itself “worked as intended” and that the incident stemmed from the attacker exploiting pre-approved authorizations from the compromised wallet. “One bad approval and boom—you’re done. That’s the dark side of DeFi: open approvals are powerful, but also deadly if you’re not careful,” wrote analyst Crypto Jargon. The sentiment was echoed across the community as warnings resurfaced. Best practices include regularly revoking approvals, avoiding unverified links, and using hardware wallets instead of relying solely on hot wallets. Cyvers confirmed this in a statement to BeInCrypto: “Yes, user side error not at protocol level,” Cyvers articulated. The stolen funds remain unswapped, held in the attacker’s contract address. “This incident shows that even experienced DeFi users remain vulnerable to sophisticated phishing schemes. By tricking the victim into granting token approvals, the attacker was able to drain $27 million from a Venus Protocol in a single transaction” said Hakan Unal Senior Security Operation Lead at Cyvers. Against this backdrop,… The post How A Venus Protocol Trader Lost $30 Million appeared on BitcoinEthereumNews.com. A dramatic incident on Venus Protocol has resulted in the loss of nearly $30 million worth of assets. While many initially suspected a hack, blockchain security analysts at Cyvers confirmed to BeInCrypto that this was a user-side mistake, not a vulnerability in the protocol itself. Phishing Scam Costs Venus Protocol User $30 Million, Not a Protocol Hack PeckShield first flagged the suspicious activity, noting that a Venus Protocol user had been drained of approximately $27 million after falling victim to a phishing scam. The attacker gained access by tricking the victim into approving a malicious transaction, which gave unlimited permissions to transfer assets from the wallet. The stolen tokens included around $19.8 million in vUSDT, $7.15 million in vUSDC, $146,000 in vXRP, $22,000 in vETH, and even 285 BTCB, representing what observers described as “generational wealth.” Defi analyst Ignas also weighed in, noting that Venus itself “worked as intended” and that the incident stemmed from the attacker exploiting pre-approved authorizations from the compromised wallet. “One bad approval and boom—you’re done. That’s the dark side of DeFi: open approvals are powerful, but also deadly if you’re not careful,” wrote analyst Crypto Jargon. The sentiment was echoed across the community as warnings resurfaced. Best practices include regularly revoking approvals, avoiding unverified links, and using hardware wallets instead of relying solely on hot wallets. Cyvers confirmed this in a statement to BeInCrypto: “Yes, user side error not at protocol level,” Cyvers articulated. The stolen funds remain unswapped, held in the attacker’s contract address. “This incident shows that even experienced DeFi users remain vulnerable to sophisticated phishing schemes. By tricking the victim into granting token approvals, the attacker was able to drain $27 million from a Venus Protocol in a single transaction” said Hakan Unal Senior Security Operation Lead at Cyvers. Against this backdrop,…

How A Venus Protocol Trader Lost $30 Million

2025/09/02 20:07
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

A dramatic incident on Venus Protocol has resulted in the loss of nearly $30 million worth of assets.

While many initially suspected a hack, blockchain security analysts at Cyvers confirmed to BeInCrypto that this was a user-side mistake, not a vulnerability in the protocol itself.

Phishing Scam Costs Venus Protocol User $30 Million, Not a Protocol Hack

PeckShield first flagged the suspicious activity, noting that a Venus Protocol user had been drained of approximately $27 million after falling victim to a phishing scam.

The attacker gained access by tricking the victim into approving a malicious transaction, which gave unlimited permissions to transfer assets from the wallet.

The stolen tokens included around $19.8 million in vUSDT, $7.15 million in vUSDC, $146,000 in vXRP, $22,000 in vETH, and even 285 BTCB, representing what observers described as “generational wealth.”

Defi analyst Ignas also weighed in, noting that Venus itself “worked as intended” and that the incident stemmed from the attacker exploiting pre-approved authorizations from the compromised wallet.

The sentiment was echoed across the community as warnings resurfaced. Best practices include regularly revoking approvals, avoiding unverified links, and using hardware wallets instead of relying solely on hot wallets.

Cyvers confirmed this in a statement to BeInCrypto:

The stolen funds remain unswapped, held in the attacker’s contract address.

Against this backdrop, Unal cautioned users against clicking or approving anything on unfamiliar websites, as phishers often impersonate official sites and make subtle domain changes.

When asked about hopes for recovery, the security expert indicated that while bug bounties are an option, mixing services make asset recovery almost impossible.

Bunni DEX Exploit Drains $8.4 Million

In a separate incident, Bunni, a decentralized exchange (DEX) built on Uniswap v4, suffered an exploit that drained over $8.4 million across Ethereum and UniChain.

Unlike the Venus case, this was a genuine vulnerability at the protocol level.

Bunni announced that it had paused all smart contract functions across networks as its team investigates:

According to GoPlus Security, the exploit stemmed from weaknesses in Bunni’s custom Liquidity Distribution Function (LDF).

Victor Tran, a blockchain developer, explained how the attacker manipulated the curve with carefully sized trades.

By repeatedly triggering miscalculations during liquidity rebalancing, the exploiter was able to withdraw more tokens than they should have, draining pools before finalizing the attack with two swap steps.

Tran emphasized that while Bunni’s hook was compromised, Uniswap v4 itself remained unaffected.

The twin incidents highlight the fragile balance between innovation and security in decentralized finance (DeFi).

Venus Protocol’s loss highlights the human element, where a single click can erase fortunes. Meanwhile, Bunni’s exploit reveals how novel mechanisms’ precision flaws can expose liquidity.

In a market where billions are at stake, one mistake, whether human or technical, can prove devastating.

Therefore, as the DeFi sector expands, user education and protocol rigor will remain critical.

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.

Source: https://beincrypto.com/venus-protocol-trader-loses-30-million-major-error-cyvers-confirms/

시장 기회
DeFi 로고
DeFi 가격(DEFI)
$0,0002009
$0,0002009$0,0002009
+%0,09
USD
DeFi (DEFI) 실시간 가격 차트

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw