Venus Protocol:
the exploit its own audit warned about, twice.
We tore apart Venus Protocol, the dominant Compound-forked lending platform on BNB Chain, across the same lending-adapted scorecard we've used throughout this series. From genuinely substantial current scale, roughly $1.47 billion in TVL and still the largest lending platform on BNB Chain, to a real, extraordinarily well-documented pattern we think deserves to be the headline: a "donation attack" vulnerability class was flagged directly in Venus's own Code4rena security audit, and the team explicitly declined to fix it, calling donations "an intentional feature with no negative side effects." That exact vulnerability class was then exploited twice, first in February 2025 on Venus's zkSync deployment (roughly $700,000 in bad debt), and again in March 2026 on BNB Chain's THE market, after an attacker spent nine months quietly accumulating roughly 84% of the token's supply cap using funds withdrawn from Tornado Cash, leaving the protocol with roughly $2.15-2.18 million in bad debt. We also found that the community had separately flagged the attacker's growing position beforehand, and the protocol again declined to intervene, citing decentralization. Venus's TVL has fallen from a $7 billion peak to roughly $1.47 billion, alongside a separate ~$14 million loss during the 2022 Terra/LUNA collapse and a ~$13 million phishing incident in 2025; and landed on a score the marketing page won't show you.
Our take, up front: Venus Protocol is a Compound-forked money market and the dominant lending platform on BNB Chain, using the same cToken-style architecture (branded vTokens) as several other protocols in this series. Real, disclosed genuinely substantial current scale: roughly $1.47 billion in TVL, still the largest lending platform on its home chain. Real, disclosed broad, isolated-market asset support across BNB Chain, Arbitrum, and Ethereum. What we can't set aside, because we think it's the single most important finding in this review: a "donation attack" vulnerability class, where an attacker deposits collateral, borrows against it, buys more of the same asset, and donates it back to manipulate the protocol's internal price tracking, was flagged directly in Venus's own Code4rena security audit. The team explicitly declined to remediate it, stating that donations were "an intentional feature with no negative side effects." That exact assessment has now been disproven twice. In February 2025, a donation attack on Venus's zkSync deployment caused over $700,000 in bad debt. In March 2026, an attacker who had spent nine months quietly accumulating roughly 84% of the THE token's supply cap, using funds sourced from Tornado Cash, executed the same attack pattern at far greater scale on BNB Chain, running the token's price up through a deposit-borrow-buy-donate loop and leaving Venus with roughly $2.15-2.18 million in bad debt after 8,048 liquidation transactions unwound the position. We also found a real, separate governance failure: the community had flagged the attacker's growing THE position as risky before the exploit, and the protocol again declined to act, citing decentralization. Real, disclosed additional historical losses: roughly $14 million in uncollateralized exposure during the May 2022 Terra/LUNA collapse, and a separate ~$13 million phishing incident affecting users in 2025. Real, disclosed, dramatic TVL decline from a $7 billion peak to roughly $1.47 billion today. We also found a real, disclosed, speculation-generating detail we're reporting factually rather than interpreting: Justin Sun, a top-5 holder of Venus's XVS governance token, moved roughly $1.95 million worth of XVS to an exchange one day after the March 2026 exploit. We weighted all of it below.
Real, extraordinarily well-documented, repeated failure: a "donation attack" vulnerability class was flagged directly in Venus's own Code4rena audit, and the team explicitly declined to fix it, calling donations "an intentional feature with no negative side effects." That exact vulnerability was then exploited twice: Feb 2025 on zkSync (~$700K bad debt) and Mar 2026 on BNB Chain's THE market (~$2.15-2.18M bad debt), the latter after an attacker spent nine months accumulating ~84% of the token's supply cap using Tornado-Cash-sourced funds. Real, disclosed separate governance failure: the community flagged the attacker's growing position beforehand, and the protocol again declined to intervene, citing decentralization. Real, disclosed additional historical losses: ~$14M in uncollateralized exposure during the 2022 Terra/LUNA collapse, and a separate ~$13M phishing incident in 2025.
Pros
- Affected supply/borrow functions were paused as a containment measure during the March 2026 incident
- Only the specific THE market was directly affected in the March 2026 incident
Cons
- A known, audit-flagged vulnerability was explicitly left unfixed, then exploited twice
- Feb 2025 (zkSync, ~$700K) and Mar 2026 (BNB Chain, ~$2.15-2.18M) both used the same attack pattern
- Community-flagged risk (the attacker's growing position) was also not acted upon before the exploit
- Separate historical losses: ~$14M (2022 Terra/LUNA) and ~$13M (2025 phishing)
Real, disclosed, still-substantial current scale: roughly $1.47 billion in TVL, the largest lending platform on BNB Chain. Real, disclosed, dramatic decline from a $7 billion historical peak, reflecting both broader market conditions and repeated, real security incidents.
Pros
- Still the dominant lending platform on BNB Chain by TVL
Cons
- TVL has fallen roughly 79% from its $7B peak
Real, disclosed functioning XVS governance token. What tempers this heavily: real, disclosed, direct governance failure on two separate occasions, declining to fix an audit-flagged vulnerability, and separately declining to act on a community-flagged risky position, both times citing decentralization as the reason for inaction. Real, disclosed, speculation-generating detail we're reporting factually: a top-5 XVS holder moved roughly $1.95 million worth of tokens to an exchange one day after the March 2026 exploit.
Pros
- Functioning on-chain XVS governance token exists
Cons
- Declined to fix an audit-flagged vulnerability that was later exploited twice
- Declined to act on a community-flagged risky position before it was exploited
Real, disclosed broad asset support (BTC, BNB, stablecoins, CAKE, THE, and others) with isolated-market listings, and multi-chain deployment across BNB Chain, Arbitrum, and Ethereum.
Pros
- Broad asset support across multiple chains and isolated markets
Cons
- Thin-liquidity asset listing directly enabled the March 2026 exploit
Real, disclosed Compound-fork cToken/vToken architecture, a familiar model for users coming from other Compound-style protocols. Real, disclosed containment response, pausing affected supply/borrow functions during the March 2026 incident.
Pros
- Familiar cToken/vToken model; disclosed containment response during the exploit
Cons
- Users must independently evaluate market risk rather than trust the platform's own listing decisions
Real, disclosed standard Compound-fork variable, utilization-based rate model. Our sources disclosed less specific, universally-quoted current rate figures than for some other protocols in this series.
Pros
- Standard, familiar variable rate model
Cons
- Less specific, universally-quoted rate figures disclosed than some competitors
Real, disclosed isolated markets support and multi-chain deployment history, though genuinely less distinctive relative to peers in this series given the recurring security concerns overshadowing the platform's feature set.
Pros
- Isolated markets and multi-chain deployment history
Cons
- Feature set is genuinely overshadowed by the platform's recurring security concerns
If you use it anyway, avoid thin-liquidity isolated markets specifically, and watch for repeat incidents.
Given the disclosed, repeated pattern of a known, audit-flagged vulnerability being exploited twice, avoid isolated markets built around thinly-liquid, low-market-cap tokens specifically, since that's precisely the profile both confirmed donation-attack incidents shared, and don't assume the platform's own asset-listing decisions have already screened out this category of risk for you.
The lowest score in this entire lending series, and the reason has nothing to do with an unknown vulnerability.
Every other severe incident we've documented in this series, Aave's bridge exploit, Compound's governance bug, even Euler's 2023 hack, involved something the team genuinely didn't see coming. Venus is different, and we think that difference matters enormously. Its own Code4rena audit told the team exactly what could go wrong with donations, and the team's response was to call it a feature. Fourteen months later, that same mechanism drained $700,000 from a different deployment. Thirteen months after that, it drained over $2 million more, this time after an attacker spent nine months in plain sight accumulating a dominant position that the community had already flagged as dangerous. We don't think this is a story about bad luck or sophisticated attackers outpacing reasonable defenses. We think it's a story about a specific, identified risk that was named twice, by an audit and by a community, and dismissed twice. A protocol can recover from a hack it didn't see coming. We're less confident this one has fully reckoned with a hack it was warned about in writing.
The scorecard above is deliberately general. Whether Venus Protocol is right for you depends heavily on which of these you already are.
The BNB Chain user who limits deposits to Venus's deepest, most established, blue-chip markets specifically
This is the profile that most avoids the specific, disclosed pattern behind both confirmed donation-attack incidents.
The user who already understands the donation-attack vulnerability class and actively avoids thin-liquidity isolated markets
Genuine awareness of this specific, disclosed risk pattern is the single most protective habit available here.
The borrower who watches for community risk flags on newer or smaller token listings and treats them seriously
Given that the protocol itself didn't act on such a flag before the March 2026 exploit, this genuinely matters more here.
Anyone who wants a lending protocol with a demonstrated record of acting on risks its own audits have identified
Aave, Compound, Kamino, and SparkLend, all reviewed earlier in this series, don't carry a comparable disclosed pattern of declining to fix an audit-flagged issue.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the two donation attacks compared directly, the "known and declined" timeline, a full historical loss ledger, and our twelfth lending-protocol comparison entry.
Two donation attacks, the same mechanism
| Feb 2025 (zkSync) | Mar 2026 (BNB Chain) | |
|---|---|---|
| Mechanism | Deposit-borrow-buy-donate loop | Same deposit-borrow-buy-donate loop |
| Bad debt | ~$700,000 | ~$2.15-2.18 million |
| Preparation | Not detailed in our sources | 9 months, ~84% of THE's supply cap accumulated via Tornado Cash-sourced funds |
| Prior warning? | The vulnerability class was already flagged in Venus's own Code4rena audit before this incident | Both the audit finding and a community-flagged risky position existed before this incident |
The second incident wasn't just the same category of vulnerability; it was a larger, more deliberate execution of the exact same technique the first incident had already demonstrated worked.
Known and declined: the timeline
| When | What happened |
|---|---|
| Before Feb 2025 | Code4rena audit flags the donation-attack vulnerability class; Venus declines to remediate, calling it "an intentional feature with no negative side effects" |
| Feb 2025 | zkSync deployment exploited via this exact vulnerability class (~$700K bad debt) |
| Jun 2025 - Mar 2026 | An attacker accumulates ~84% of THE's supply cap; the community flags this position as risky; the protocol declines to act, citing decentralization |
| Mar 15-16, 2026 | BNB Chain THE market exploited via the same donation-attack mechanism (~$2.15-2.18M bad debt) |
We want to be precise about why this timeline matters to our score: two separate, specific warnings preceded two separate, real losses, using the same underlying mechanism both times.
A fuller loss ledger
| Date | Event | Approximate loss |
|---|---|---|
| May 2022 | Terra/LUNA collapse; uncollateralized exposure absorbed by Venus (systemic market failure, not direct exploitation) | ~$14 million |
| 2025 | Phishing attack affecting users | ~$13 million |
| Feb 2025 | Donation attack, zkSync deployment | ~$700,000 |
| Mar 2026 | Donation attack, BNB Chain THE market | ~$2.15-2.18 million |
We're presenting these as four distinct events with different root causes (systemic market failure, user-targeted phishing, and two protocol-level exploits) rather than collapsing them into one generic "history of losses" line.
Lending protocols, side by side (series continues)
| Aave | Compound | Kamino | Morpho | SparkLend | Euler | Jupiter Lend | Maple | Venus | |
|---|---|---|---|---|---|---|---|---|---|
| Most severe disclosed history | $292M bridge exploit | $161.7M governance bug | None found | $18M vault loss | None found | $197-240M exploit, recovered | None on contracts | ~$50-54M in 2022 defaults | Known vuln., exploited twice: $700K + $2.15-2.18M |
| Was the risk previously flagged? | No, third-party bridge risk | No, upgrade bug | N/A | Partially, permissionless market design | N/A | No, novel bug | N/A | No, credit misrepresentation | Yes, by the team's own audit and separately by the community |
Venus is the only protocol in this series where the exploited vulnerability was explicitly identified and consciously left unaddressed before causing real, repeated losses.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. Coverage of Venus is dominated by incident-specific reporting on the March 2026 exploit; we've used only the sources that offer a general assessment of the protocol rather than pure news coverage of the incident itself.
Our score lands meaningfully below the aggregated industry average; even the more critical general sources we found don't weight the "flagged by an audit and explicitly declined" detail as heavily as our methodology does, treating it as one data point among several rather than the defining fact of the review.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
Yes, twice via the same donation-attack vulnerability: February 2025 on a zkSync deployment (~$700,000 bad debt) and March 2026 on BNB Chain's THE market (~$2.15-2.18 million bad debt). It also absorbed ~$14 million in exposure during the 2022 Terra/LUNA collapse and a separate ~$13 million phishing incident in 2025.
An attacker deposits a token as collateral, borrows against it, uses the proceeds to buy more of the same token, and "donates" it back into the pool, artificially inflating the token's tracked price. This lets the attacker borrow far more than their real position should support.
Yes. The donation-attack vulnerability class was flagged directly in Venus's own Code4rena security audit before the February 2025 incident. The team explicitly declined to remediate it, stating that donations were "an intentional feature with no negative side effects."
An attacker spent nine months, starting June 2025, quietly accumulating roughly 84% of the THE token's supply cap using funds sourced from Tornado Cash. On March 15, 2026, they executed the donation-attack loop at scale, pushing THE's price up sharply before 8,048 liquidation transactions unwound the position, leaving Venus with roughly $2.15-2.18 million in bad debt.
Yes. The attacker's growing THE position had been flagged by the community before the exploit, but the protocol declined to act, citing decentralization as the reason for inaction.
Roughly $1.47 billion, still the largest lending platform on BNB Chain, though down sharply from a $7 billion historical peak.
Justin Sun, a top-5 holder of Venus's XVS governance token, moved roughly $1.95 million worth of XVS to an exchange one day after the March 2026 exploit. This prompted market speculation, though we're reporting the transaction itself rather than asserting any wrongdoing.
Both confirmed donation attacks targeted specific, thinly-liquid isolated markets rather than the platform's major, deep-liquidity markets. Limiting exposure to established, high-liquidity assets meaningfully reduces exposure to this specific, disclosed attack pattern, though it doesn't eliminate general platform risk.
More Reviews
Ledn – Crypto Lending & Borrowing Review
Score: 75/100. Highest CeFi score in this series: 10 straight PoR attestations, explicit no-re-lending pledge, never lost customer funds.
Read MoreAave – Crypto Lending & Borrowing Review
Score: 69.5/100. Category leader hit hardest by the Apr 2026 KelpDAO crisis: $124-230M bad debt, its largest liquidity event yet.
Read MoreCompound – Crypto Lending & Borrowing Review
Score: 63.25/100. Pioneer whose 2021 self-inflicted $161.7M COMP bug remains its scar, though its caution spared it in Apr 2026.
Read MoreCoinRabbit – Crypto Lending & Borrowing Review
Score: 50.5/100. Fast, no-KYC lending with a great product, but no named founder, no PoR, and vague licensing behind it.
Read More



