ChainBleedv0.1 · open intel
← back to feed·BSCSOCIAL-ENGINEERING2021-05-18 · 5y ago
Incident · SLOWMIST

Venus

Lack of Liquidity
Estimated loss
$145.00M
VERDICT —OUT OF SCOPE
Root cause is social engineering — privileged personnel deceived into authorizing the drain. Contract behaved as written. Defense lives in process controls (multi-party approval, M-of-N signoff windows), not in smart-contract review.
▰ METHOD
SOCIAL ENGINEERING
SOCIAL-ENGINEERING
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

On the evening of May 18, the BSC-based DeFi lending platform Venus token XVS was doubled by the giant whale. After that, XVS was used as collateral to borrow and transfer BTC and ETH worth hundreds of millions of dollars. Since then, the price of collateral XVS is large. It fell and faced liquidation, but due to insufficient liquidity in the XVS market, the system failed to liquidate in time, resulting in a huge shortfall of hundreds of millions of dollars in Venus. On the 30th, Venus officially released an article that disclosed the process and results of the incident. The survey showed that the liquidator made a profit of about 20 million U.S. dollars, and the seller made a profit of about 55 million U.S. dollars; the "scalper" made a profit of about 2 million U.S. dollars; the 0xef044 address account had a net loss of about 66 million U.S. dollars. Secondly, its address attribution is based on the Swipe escrow address used on Binance, so there is no insider trading. The agreement lost approximately $77 million due to market fluctuations. VGP will recover approximately US$77 million from the distribution fund, and formulate a community recovery plan for XVS holders and others in the form of airdrops from the distribution fund and agreement income. Attack method (per SlowMist): Lack of Liquidity. Reported loss: $ 145,000,000.

Primary source
https://quillhashteam.medium.com/200-m-venus-protocol-hack-analysis-b044af76a1ae
Sourced from
slowmist
Technical record
chain
bsc
protocol
Venus
bug_class
social-engineering
date_occurred
2021-05-18
loss_usd
$145,000,000
source_id
sm:venus::2021-05-18
Related — same bug class· social-engineering
2026-05-11
1mo ago
SOL
Roaring Kitty X Account → $RKC memecoin pump-dump
X account takeover → coordinated memecoin pump-and-dump on Pump.fun
social-engineering
$2.86M
OUT OF SCOPE
2026-04-01
2mo ago
SOL
Drift Protocol
DPRK-linked Privileged-Access Drain
social-engineering
$286.00M
OUT OF SCOPE
2026-02-23
3mo ago
WLFI
Social Engineering
social-engineering
OUT OF SCOPE
2025-09-01
9mo ago
BSC
OlaXBT
Multisig wallet Social Engineering Exploit
social-engineering
$2.00M
OUT OF SCOPE
2025-07-24
10mo ago
MULTI
WOO X
Social Engineering
social-engineering
$14.00M
OUT OF SCOPE
2025-04-27
1y ago
QuantMaster
Insider Manipulation
social-engineering
$100.0K
OUT OF SCOPE
ChainBleed — live web3 threat intelligence