Venus Protocol; Reviewed & Scored | The Block Note
Lending & Borrowing Protocol Review · Updated August 2026

Venus Protocol:
the exploit its own audit warned about, twice.

We tore apart Venus Protocol, the dominant Compound-forked lending platform on BNB Chain, across the same lending-adapted scorecard we've used throughout this series. From genuinely substantial current scale, roughly $1.47 billion in TVL and still the largest lending platform on BNB Chain, to a real, extraordinarily well-documented pattern we think deserves to be the headline: a "donation attack" vulnerability class was flagged directly in Venus's own Code4rena security audit, and the team explicitly declined to fix it, calling donations "an intentional feature with no negative side effects." That exact vulnerability class was then exploited twice, first in February 2025 on Venus's zkSync deployment (roughly $700,000 in bad debt), and again in March 2026 on BNB Chain's THE market, after an attacker spent nine months quietly accumulating roughly 84% of the token's supply cap using funds withdrawn from Tornado Cash, leaving the protocol with roughly $2.15-2.18 million in bad debt. We also found that the community had separately flagged the attacker's growing position beforehand, and the protocol again declined to intervene, citing decentralization. Venus's TVL has fallen from a $7 billion peak to roughly $1.47 billion, alongside a separate ~$14 million loss during the 2022 Terra/LUNA collapse and a ~$13 million phishing incident in 2025; and landed on a score the marketing page won't show you.

Type Non-Custodial Lending Protocol (Compound Fork) Platforms Web · BNB Chain, Arbitrum, Ethereum Rates Variable, utilization-based Discount Offer None
venus
Lending Protocol
Audit flagged the exploit vector; team declined to fix
Same bug hit twice: Feb 2025 + Mar 2026

Our take, up front: Venus Protocol is a Compound-forked money market and the dominant lending platform on BNB Chain, using the same cToken-style architecture (branded vTokens) as several other protocols in this series. Real, disclosed genuinely substantial current scale: roughly $1.47 billion in TVL, still the largest lending platform on its home chain. Real, disclosed broad, isolated-market asset support across BNB Chain, Arbitrum, and Ethereum. What we can't set aside, because we think it's the single most important finding in this review: a "donation attack" vulnerability class, where an attacker deposits collateral, borrows against it, buys more of the same asset, and donates it back to manipulate the protocol's internal price tracking, was flagged directly in Venus's own Code4rena security audit. The team explicitly declined to remediate it, stating that donations were "an intentional feature with no negative side effects." That exact assessment has now been disproven twice. In February 2025, a donation attack on Venus's zkSync deployment caused over $700,000 in bad debt. In March 2026, an attacker who had spent nine months quietly accumulating roughly 84% of the THE token's supply cap, using funds sourced from Tornado Cash, executed the same attack pattern at far greater scale on BNB Chain, running the token's price up through a deposit-borrow-buy-donate loop and leaving Venus with roughly $2.15-2.18 million in bad debt after 8,048 liquidation transactions unwound the position. We also found a real, separate governance failure: the community had flagged the attacker's growing THE position as risky before the exploit, and the protocol again declined to act, citing decentralization. Real, disclosed additional historical losses: roughly $14 million in uncollateralized exposure during the May 2022 Terra/LUNA collapse, and a separate ~$13 million phishing incident affecting users in 2025. Real, disclosed, dramatic TVL decline from a $7 billion peak to roughly $1.47 billion today. We also found a real, disclosed, speculation-generating detail we're reporting factually rather than interpreting: Justin Sun, a top-5 holder of Venus's XVS governance token, moved roughly $1.95 million worth of XVS to an exchange one day after the March 2026 exploit. We weighted all of it below.

Real, extraordinarily well-documented, repeated failure: a "donation attack" vulnerability class was flagged directly in Venus's own Code4rena audit, and the team explicitly declined to fix it, calling donations "an intentional feature with no negative side effects." That exact vulnerability was then exploited twice: Feb 2025 on zkSync (~$700K bad debt) and Mar 2026 on BNB Chain's THE market (~$2.15-2.18M bad debt), the latter after an attacker spent nine months accumulating ~84% of the token's supply cap using Tornado-Cash-sourced funds. Real, disclosed separate governance failure: the community flagged the attacker's growing position beforehand, and the protocol again declined to intervene, citing decentralization. Real, disclosed additional historical losses: ~$14M in uncollateralized exposure during the 2022 Terra/LUNA collapse, and a separate ~$13M phishing incident in 2025.

Why this scores among the lowest in this entire series: this isn't an unknown vulnerability that slipped past review, it's a specific, audit-flagged risk the team was warned about directly and chose not to fix, and the same risk then materialized twice, a pattern we treat as more serious than a single, unforeseen incident of any size.

Pros

  • Affected supply/borrow functions were paused as a containment measure during the March 2026 incident
  • Only the specific THE market was directly affected in the March 2026 incident

Cons

  • A known, audit-flagged vulnerability was explicitly left unfixed, then exploited twice
  • Feb 2025 (zkSync, ~$700K) and Mar 2026 (BNB Chain, ~$2.15-2.18M) both used the same attack pattern
  • Community-flagged risk (the attacker's growing position) was also not acted upon before the exploit
  • Separate historical losses: ~$14M (2022 Terra/LUNA) and ~$13M (2025 phishing)

Real, disclosed, still-substantial current scale: roughly $1.47 billion in TVL, the largest lending platform on BNB Chain. Real, disclosed, dramatic decline from a $7 billion historical peak, reflecting both broader market conditions and repeated, real security incidents.

Why this scores at the midpoint: still-substantial absolute scale is a real positive, tempered heavily by a dramatic, real decline directly connected to repeated security failures.

Pros

  • Still the dominant lending platform on BNB Chain by TVL

Cons

  • TVL has fallen roughly 79% from its $7B peak

Real, disclosed functioning XVS governance token. What tempers this heavily: real, disclosed, direct governance failure on two separate occasions, declining to fix an audit-flagged vulnerability, and separately declining to act on a community-flagged risky position, both times citing decentralization as the reason for inaction. Real, disclosed, speculation-generating detail we're reporting factually: a top-5 XVS holder moved roughly $1.95 million worth of tokens to an exchange one day after the March 2026 exploit.

Why this scores among the lowest in this series: citing decentralization as a reason not to intervene on a specifically identified, growing risk is a real, disclosed governance failure, repeated across two separate warning signals before the same outcome occurred.

Pros

  • Functioning on-chain XVS governance token exists

Cons

  • Declined to fix an audit-flagged vulnerability that was later exploited twice
  • Declined to act on a community-flagged risky position before it was exploited

Real, disclosed broad asset support (BTC, BNB, stablecoins, CAKE, THE, and others) with isolated-market listings, and multi-chain deployment across BNB Chain, Arbitrum, and Ethereum.

Why this scores at the midpoint: genuinely broad asset support is real, tempered directly by the fact that permissive listing of a thinly-liquid asset (THE) is precisely what enabled the March 2026 exploit.

Pros

  • Broad asset support across multiple chains and isolated markets

Cons

  • Thin-liquidity asset listing directly enabled the March 2026 exploit

Real, disclosed Compound-fork cToken/vToken architecture, a familiar model for users coming from other Compound-style protocols. Real, disclosed containment response, pausing affected supply/borrow functions during the March 2026 incident.

Why this scores at the midpoint: a familiar, workable interface, tempered by the reality that a genuinely informed user needs to actively evaluate individual market risk rather than trust the platform's own listing decisions.

Pros

  • Familiar cToken/vToken model; disclosed containment response during the exploit

Cons

  • Users must independently evaluate market risk rather than trust the platform's own listing decisions

Real, disclosed standard Compound-fork variable, utilization-based rate model. Our sources disclosed less specific, universally-quoted current rate figures than for some other protocols in this series.

Why this scores below the midpoint: a standard, functional rate model, tempered by less specific disclosed rate data and the broader context of repeated security incidents affecting overall trust in the platform's risk parameters.

Pros

  • Standard, familiar variable rate model

Cons

  • Less specific, universally-quoted rate figures disclosed than some competitors

Real, disclosed isolated markets support and multi-chain deployment history, though genuinely less distinctive relative to peers in this series given the recurring security concerns overshadowing the platform's feature set.

Pros

  • Isolated markets and multi-chain deployment history

Cons

  • Feature set is genuinely overshadowed by the platform's recurring security concerns
Where to get it

If you use it anyway, avoid thin-liquidity isolated markets specifically, and watch for repeat incidents.

Given the disclosed, repeated pattern of a known, audit-flagged vulnerability being exploited twice, avoid isolated markets built around thinly-liquid, low-market-cap tokens specifically, since that's precisely the profile both confirmed donation-attack incidents shared, and don't assume the platform's own asset-listing decisions have already screened out this category of risk for you.

0/ 100

The lowest score in this entire lending series, and the reason has nothing to do with an unknown vulnerability.

Every other severe incident we've documented in this series, Aave's bridge exploit, Compound's governance bug, even Euler's 2023 hack, involved something the team genuinely didn't see coming. Venus is different, and we think that difference matters enormously. Its own Code4rena audit told the team exactly what could go wrong with donations, and the team's response was to call it a feature. Fourteen months later, that same mechanism drained $700,000 from a different deployment. Thirteen months after that, it drained over $2 million more, this time after an attacker spent nine months in plain sight accumulating a dominant position that the community had already flagged as dangerous. We don't think this is a story about bad luck or sophisticated attackers outpacing reasonable defenses. We think it's a story about a specific, identified risk that was named twice, by an audit and by a community, and dismissed twice. A protocol can recover from a hack it didn't see coming. We're less confident this one has fully reckoned with a hack it was warned about in writing.

Best forUsers who limit exposure to Venus's most established, deepest-liquidity markets and actively avoid newer or thinly-traded asset listings
Not forAnyone who wants a lending protocol with a demonstrated record of acting on risks its own audits and community have already identified
Score Ledger
venus protocol · 7 line items
01Security9.0
02Liquidity11.0
03Decentralization4.5
04Assets6.0
05UX6.0
06Rates5.5
07Extras2.5
TOTAL44.5
≈ 45 / 100; Warned twice, exploited twice

The scorecard above is deliberately general. Whether Venus Protocol is right for you depends heavily on which of these you already are.

Best fit

The BNB Chain user who limits deposits to Venus's deepest, most established, blue-chip markets specifically

This is the profile that most avoids the specific, disclosed pattern behind both confirmed donation-attack incidents.

Good fit

The user who already understands the donation-attack vulnerability class and actively avoids thin-liquidity isolated markets

Genuine awareness of this specific, disclosed risk pattern is the single most protective habit available here.

Workable fit

The borrower who watches for community risk flags on newer or smaller token listings and treats them seriously

Given that the protocol itself didn't act on such a flag before the March 2026 exploit, this genuinely matters more here.

Poor fit

Anyone who wants a lending protocol with a demonstrated record of acting on risks its own audits have identified

Aave, Compound, Kamino, and SparkLend, all reviewed earlier in this series, don't carry a comparable disclosed pattern of declining to fix an audit-flagged issue.

The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the two donation attacks compared directly, the "known and declined" timeline, a full historical loss ledger, and our twelfth lending-protocol comparison entry.

Two donation attacks, the same mechanism

Feb 2025 (zkSync)Mar 2026 (BNB Chain)
MechanismDeposit-borrow-buy-donate loopSame deposit-borrow-buy-donate loop
Bad debt~$700,000~$2.15-2.18 million
PreparationNot detailed in our sources9 months, ~84% of THE's supply cap accumulated via Tornado Cash-sourced funds
Prior warning?The vulnerability class was already flagged in Venus's own Code4rena audit before this incidentBoth the audit finding and a community-flagged risky position existed before this incident

The second incident wasn't just the same category of vulnerability; it was a larger, more deliberate execution of the exact same technique the first incident had already demonstrated worked.

Known and declined: the timeline

WhenWhat happened
Before Feb 2025Code4rena audit flags the donation-attack vulnerability class; Venus declines to remediate, calling it "an intentional feature with no negative side effects"
Feb 2025zkSync deployment exploited via this exact vulnerability class (~$700K bad debt)
Jun 2025 - Mar 2026An attacker accumulates ~84% of THE's supply cap; the community flags this position as risky; the protocol declines to act, citing decentralization
Mar 15-16, 2026BNB Chain THE market exploited via the same donation-attack mechanism (~$2.15-2.18M bad debt)

We want to be precise about why this timeline matters to our score: two separate, specific warnings preceded two separate, real losses, using the same underlying mechanism both times.

A fuller loss ledger

DateEventApproximate loss
May 2022Terra/LUNA collapse; uncollateralized exposure absorbed by Venus (systemic market failure, not direct exploitation)~$14 million
2025Phishing attack affecting users~$13 million
Feb 2025Donation attack, zkSync deployment~$700,000
Mar 2026Donation attack, BNB Chain THE market~$2.15-2.18 million

We're presenting these as four distinct events with different root causes (systemic market failure, user-targeted phishing, and two protocol-level exploits) rather than collapsing them into one generic "history of losses" line.

Lending protocols, side by side (series continues)

AaveCompoundKaminoMorphoSparkLendEulerJupiter LendMapleVenus
Most severe disclosed history$292M bridge exploit$161.7M governance bugNone found$18M vault lossNone found$197-240M exploit, recoveredNone on contracts~$50-54M in 2022 defaultsKnown vuln., exploited twice: $700K + $2.15-2.18M
Was the risk previously flagged?No, third-party bridge riskNo, upgrade bugN/APartially, permissionless market designN/ANo, novel bugN/ANo, credit misrepresentationYes, by the team's own audit and separately by the community

Venus is the only protocol in this series where the exploited vulnerability was explicitly identified and consciously left unaddressed before causing real, repeated losses.

We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. Coverage of Venus is dominated by incident-specific reporting on the March 2026 exploit; we've used only the sources that offer a general assessment of the protocol rather than pure news coverage of the incident itself.

The Block Note (us)N/A / 100
Industry averageN/A / 100

Our score lands meaningfully below the aggregated industry average; even the more critical general sources we found don't weight the "flagged by an audit and explicitly declined" detail as heavily as our methodology does, treating it as one data point among several rather than the defining fact of the review.

SourceScoreType

Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.

Yes, twice via the same donation-attack vulnerability: February 2025 on a zkSync deployment (~$700,000 bad debt) and March 2026 on BNB Chain's THE market (~$2.15-2.18 million bad debt). It also absorbed ~$14 million in exposure during the 2022 Terra/LUNA collapse and a separate ~$13 million phishing incident in 2025.

An attacker deposits a token as collateral, borrows against it, uses the proceeds to buy more of the same token, and "donates" it back into the pool, artificially inflating the token's tracked price. This lets the attacker borrow far more than their real position should support.

Yes. The donation-attack vulnerability class was flagged directly in Venus's own Code4rena security audit before the February 2025 incident. The team explicitly declined to remediate it, stating that donations were "an intentional feature with no negative side effects."

An attacker spent nine months, starting June 2025, quietly accumulating roughly 84% of the THE token's supply cap using funds sourced from Tornado Cash. On March 15, 2026, they executed the donation-attack loop at scale, pushing THE's price up sharply before 8,048 liquidation transactions unwound the position, leaving Venus with roughly $2.15-2.18 million in bad debt.

Yes. The attacker's growing THE position had been flagged by the community before the exploit, but the protocol declined to act, citing decentralization as the reason for inaction.

Roughly $1.47 billion, still the largest lending platform on BNB Chain, though down sharply from a $7 billion historical peak.

Justin Sun, a top-5 holder of Venus's XVS governance token, moved roughly $1.95 million worth of XVS to an exchange one day after the March 2026 exploit. This prompted market speculation, though we're reporting the transaction itself rather than asserting any wrongdoing.

Both confirmed donation attacks targeted specific, thinly-liquid isolated markets rather than the platform's major, deep-liquidity markets. Limiting exposure to established, high-liquidity assets meaningfully reduces exposure to this specific, disclosed attack pattern, though it doesn't eliminate general platform risk.

Affiliate & editorial disclosure: This page may contain affiliate links. If you buy through one, we may earn a commission at no extra cost to you. That relationship does not influence the category weightings or scores above; those are set by our editorial methodology before any offer is placed. Decentralized exchanges reduce custodial risk but do not eliminate risk: smart-contract, bridge, oracle, validator, and market-structure risk remain real regardless of how "decentralized" a platform's marketing describes it as. Leverage trading can result in losses exceeding your initial deposit. Nothing here is financial advice.
Features, pricing, and security details verified against public sources as of Aug 2026; always confirm current terms directly with Venus Protocol.

More Reviews