Connect with us

Crypto World

Venus Protocol Hit by $3.7M Supply-Cap Attack

Published

on

Crypto Breaking News

Venus Protocol, a decentralized lending and borrowing platform, reported on Sunday that it detected suspicious trading activity in the liquidity pool for the Thena (THE) token, the native asset of the Thena DeFi protocol. The anomaly appeared to affect only two pools—CAKE, the native token of PancakeSwap, and THE—and prompted an immediate, precautionary pause on all borrows and withdrawals related to THE. The pause will remain in place while investigators review the activity and determine appropriate next steps.

Key takeaways

  • Venus Protocol paused all THE borrows and withdrawals amid an active investigation into unusual pool activity, signaling an abundance of caution during a multi‑asset incident.
  • Allez Labs, described as Venus Protocol’s risk manager, attributed the episode to a supply cap attack executed in two phases, combining a rapid accumulation of the THE market cap with a lending attack.
  • The attacker reportedly used the Theta token as collateral to borrow large quantities of CAKE, USDC, BNB, and BTC, amplifying a liquidity crunch in the affected pools.
  • Total losses from the attack are estimated to exceed $3.7 million, according to Wu Blockchain, with additional halts imposed on low-liquidity tokens as a precaution.
  • Thena’s THE price moved lower in reaction to the incident, trading around $0.2255 at the time of reporting, down roughly 17% over the prior 24 hours, per market data.
  • The incident underscores ongoing security and cyber-risk challenges in DeFi, even as overall hack losses in February registered a notable decline before phishing and social‑engineering threats rose again.

Tickers mentioned: $BTC, $CAKE, $USDC, $BNB, $THE, $THETA

Sentiment: Neutral

Price impact: Negative. THE’s price fell about 17% in the 24 hours leading up to the report as details of the incident emerged and risk concerns escalated.

Trading idea (Not Financial Advice): Hold. Monitor the investigation’s findings, the status of THE pool, and any subsequent risk‑management measures announced by Venus Protocol or its partners.

Advertisement

Market context: The attack arrives as the sector grapples with sophisticated on‑chain exploits and the broader DeFi liquidity environment. February’s data from PeckShield showed total crypto losses from hacks at $49 million—the lowest in nearly a year—yet security incidents continue to shift toward social engineering and phishing, indicating that user education remains critical amid growing ecosystem complexity.

Why it matters

The Venus Protocol incident highlights the fragility that can accompany high‑leverage DeFi ecosystems where attackers exploit complex interactions across multiple pools. By leveraging THE as collateral to borrow CAKE, USDC, BNB, and BTC, the attacker sought to lock in a sizable position while exploiting liquidity imbalances in the THE pool. The decision to pause all THE borrows and withdrawals signals a governance and risk team that is prioritizing containment and forgoing near‑term liquidity for long‑term safety.

From a risk‑management perspective, the episode exposes the limits of automated checks when faced with layered attack vectors, including supply cap strategies and cross‑pool collateralization. Allez Labs’ assessment that the attack unfolded in two phases—first accumulating a dominant chunk of THE’s supply, then leveraging it to drain liquidity via lending—underscores how attackers may align price manipulation, liquidity capture, and debt creation in a coordinated sequence. The disclosure also reinforces the value of explicit risk monitoring partners in DeFi ecosystems, where independent assessments can accelerate detection and response.

For users and lenders, the event serves as a reminder of the importance of cautious borrowing, diversified collateral, and awareness of pool liquidity conditions across platforms. While DeFi continues to deliver permissionless access to capital, incidents like these demonstrate that security controls—such as circuit breakers and pause protections—remain essential tools in mitigating cascading losses during abnormal markets. The rapid public disclosure by Venus Protocol and the involvement of a risk manager in framing the incident illustrate a broader industry push toward transparency in the wake of major exploits.

Advertisement

The February security landscape—with a pivot toward phishing and social‑engineering schemes despite a fall in hack losses—also reflects the ongoing tension between on‑chain mechanics and off‑chain social risk. Industry observers note that as DeFi grows, attackers increasingly target user interfaces, private keys, and approval workflows, making user education a critical component of systemic resilience. The current case reinforces the need for robust auditing, real‑time monitoring, and cross‑protocol collaboration to reduce the blast radius of such attacks.

The full narrative around the THE pool incident and its implications for DeFi risk management is still developing, but the immediate actions taken by Venus Protocol illustrate a measured approach to crisis containment, prioritizing asset preservation and orderly disclosure over rapid liquidity restoration.

What to watch next

  • Updates from Venus Protocol on the investigation’s progress and the duration of the THE pool pause.
  • Announcements from Allez Labs detailing the root cause analysis and any proposed mitigations or governance proposals.
  • Whether any portion of the stolen assets are recovered, or if liquidations and collateral redemptions proceed as investigators gather more data.
  • Any changes to liquidity provisions for THE, CAKE, and related assets across Venus and connected DeFi ecosystems, including potential audits or security enhancements.
  • Regulatory or platform‑level responses that might affect cross‑pool collateralization or risk‑rating frameworks in DeFi lending markets.

Sources & verification

  • Venus Protocol official status on X detailing the pause and ongoing investigation: https://x.com/VenusProtocol/status/2033206484935344251
  • Allez Labs’ remarks identifying the two‑phase supply cap and lending attack: https://x.com/AllezLabs/status/2033239532355858536
  • Wu Blockchain reporting on total losses tied to the incident: https://x.com/WuBlockchain/status/2033173968346120495
  • THE price reference on CoinMarketCap: https://coinmarketcap.com/currencies/thena/
  • Nominis monthly report on February crypto hacks and attacks: https://www.nominis.io/insights/nominis-monthly-report-crypto-hacks-and-attacks-in-february-2026

Key figures and next steps

Rewritten Article Body

Market reaction and key details

The Venus Protocol incident began with a signal of irregular activity centered on the Thena (THE) pool, prompting an immediate, protocol‑level pause on THE borrows and withdrawals. The move, described as precautionary, aims to prevent a further spillover while investigators parse the sequence of events that allowed the attacker to capitalize on THE liquidity. The pause is explicit in Venus’ communications and remains in place until a full assessment is complete.

The attacker’s approach, as outlined by Allez Labs, involved a supply cap attack designed to accumulate a dominant share of THE’s on‑chain supply in two stages. In parallel, a lending attack was executed, leveraging Theta (CRYPTO: THETA) as collateral. This allowed the attacker to borrow a substantial amount of CAKE (CRYPTO: CAKE), USDC (CRYPTO: USDC), BNB (CRYPTO: BNB), and BTC (CRYPTO: BTC). The combination of market capture and debt creation appears to have stretched the liquidity of the affected pools and increased risk exposure across Venus’ lending market.

Public disclosures show that 6.67 million CAKE, 1.58 million USDC, 2,801 BNB, and 20 BTC were among the assets borrowed using Theta as collateral. Out of an abundance of caution, Venus also halted withdrawals and borrowing for other tokens with relatively low liquidity on the platform, a decision that underscores the potential for cross‑asset contagion in a congestion event. The total value implicated in the attack has since been cited as over $3.7 million, amplifying concerns about the pace at which DeFi platforms can respond to sophisticated exploits.

Advertisement

At the time of reporting, THE traded around $0.2255, reflecting a material drop as traders digested the security event and its implications for the DeFi stack. The price move aligns with typical market responses to exploit disclosures, where risk premia rise and liquidity pools tighten in the wake of uncertain asset backing. The broader price action for THE remains contingent on the recovery of funds, ongoing risk disclosures, and the ability of Venus to restore user confidence through transparent remediation efforts.

Investigators contacted by the press noted that Theta’s role as collateral injected a cross‑protocol dynamic into the attack scenario. Theta is a major participant in its own ecosystem, and the incident highlights how collateral quality and pool design interact in complex ways when attackers execute multi‑step strategies. The breakdown of normal pool behavior, in conjunction with a targeted accumulation of THE, illustrates the evolving risk landscape for liquid markets where yield farming, flash loans, and cross‑collateralization intersect with governance and liquidity provisioning.

From a governance and ecosystem perspective, the incident reinforces the importance of real‑time risk frameworks and independent risk management capabilities within DeFi protocols. The collaboration between Venus Protocol, Allez Labs, and other security researchers is a positive sign that platforms are moving toward more robust, auditable controls to detect and defuse such attacks before they precipitate broader losses. It also emphasizes the need for user education around approval flow vigilance and the dangers of reusing keys or compromising wallets during high‑volatility periods.

As the investigation unfolds, market participants will be watching how Venus communicates remediation plans, what protections are introduced to prevent similar exploits, and how liquidity recovery strategies are executed to minimize downtime for affected pools. The incident also contributes to the ongoing dialogue about the resilience of cross‑chain DeFi, the role of risk managers in rapidly identifying and tokenizing threats, and the importance of rapid, transparent disclosures in maintaining user trust during periods of stress.

Advertisement

In sum, the Venus Protocol event illustrates both the ingenuity of attackers and the adaptive measures that DeFi platforms are employing to safeguard users. While the exact financial impact is still being quantified, the incident underscores the need for continuous improvement in risk assessment, rapid incident response, and robust governance processes in decentralized finance ecosystems.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Crypto World

China’s factory output and consumption beat forecasts, while property investment contraction slows

Published

on

China's factory output and consumption beat forecasts, while property investment contraction slows

Staff sort parcels on the mail sorting assembly line at the Postal Delivery Logistics Joint Distribution Center in Mengshan County, Wuzhou City, Guangxi Province, China, on January 28, 2026. (Photo by Costfoto/NurPhoto via Getty Images)

Costfoto | Nurphoto | Getty Images

China’s economy started on a strong footing this year, with consumption and production both beating expectations as holiday spending and strong foreign demand provided an early boost.

Advertisement

Retail sales for the first two months of the year rose 2.8% from a year earlier, beating economists’ forecast for a 2.5% growth, while reflecting a notable slowdown from the 4% growth in the January-February period in 2025.

Industrial output climbed 6.3%, also exceeding expectations for a 5% jump in a Reuters poll. Industrial production has been a relative bright spot in the world’s second-largest economy, thanks to resilient external demand, particularly from European and Southeast Asian nations.

Investment in fixed assets, which includes property, advanced 1.8% from a year earlier, compared with the forecast of a 2.1% drop. Investment in real estate development declined further as a real estate crisis dragged on, falling 11.1% in January and February, moderating from the 17.2% drop in 2025.

The fixed asset investment saw an unprecedented slump in 2025, declining 3.8% year over year, as a deepening property downturn and tighter constraints on local governments’ borrowing hampered one of China’s traditional growth drivers.

Advertisement

Chinese leadership unveiled its annual economic goals for 2026 just last week, tamping down the GDP growth target to a range of 4.5% to 5%, the least ambitious goal on record going back to the early 1990s.

This is breaking news. Please refresh for updates.

Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.

Source link

Advertisement
Continue Reading

Crypto World

Aave Unveils Aave Shield After $50M Token Swap Mishap

Published

on

Crypto Breaking News

Decentralized finance protocol Aave is moving to tighten protections after a dramatic interaction on the CoW Swap interface led to a roughly $50 million loss in a single trade. The proposed safeguard, still described as a forthcoming feature, aims to cap price impact on swaps executed through Aave’s own interface, reflecting ongoing concerns about liquidity fragmentation and the risks that automated market-making can pose in stressed markets. The incident centered on a trader who attempted to swap about $50.4 million worth of USDt for Aave’s native token through CoW Swap but received only around $36,500 of the token, underscoring the fragility of routing in an illiquid environment. A substantial portion of the loss was magnified by a Maximal Extractable Value bot that executed a sandwich sequence, capturing nearly $10 million in the process.

Key takeaways

  • Aave plans to deploy a feature called Aave Shield that blocks swaps with a price impact above 25% when using the Aave interface, addressing a recent large-value trade failure.
  • The high-stakes trade involved converting USDt for AAVE via CoW Swap, where liquidity gaps produced a final payout of only a fraction of the intended amount, illustrating liquidity fragmentation concerns.
  • A MEV bot executed a sandwich attack in the same event, contributing roughly $10 million to the total loss and highlighting incentive structures that attackers leverage in DeFi trades.
  • A user reportedly saw multiple warnings on the platform, including notes that a route might return less due to low liquidity or small order size, and explicitly confirmed a potential 100% value loss before finalizing the swap.
  • CoW DAO attributed the extreme price impact to liquidity deficiencies and several infrastructure failures, including an outdated gas limit that hindered better-priced quotes.

Tickers mentioned: $AAVE, $USDT

Price impact: Negative — the trade exceeded a 25% price-improvement threshold, contributing to a loss of about $50 million and underscoring liquidity-driven risk in cross-exchange routing.

Market context: The episode underscores ongoing fragility in DeFi trading infrastructure amid liquidity fragmentation, MEV-driven risks, and the need for clearer risk disclosures and guardrails as users navigate multiple on-chain venues.

Why it matters

In decentralized finance, liquidity is the lifeblood that enables large swaps to execute without slippage. When liquidity pockets are thin or misaligned, even sophisticated routing engines can deliver outcomes far from the expected fair value, especially on trades of tens of millions of dollars. The Aave Shield proposal signals a shift toward user protections that don’t necessarily rely on post-trade refunds or off-chain interventions. By setting a 25% price-impact guardrail, the protocol aims to prevent users from unintentionally triggering extreme slippage, a feature that could reduce the likelihood of catastrophic outcomes in high-volume trades conducted on Aave’s interface.

Advertisement

The incident also spotlights the persistent incentives for attackers within DeFi ecosystems. A MEV bot earned an estimated $10 million through a sandwich attack tied to the same trade, illustrating how opportunistic front-running and optimization strategies can exploit routing inefficiencies. This reality reinforces the argument that security and risk controls in DeFi must address both the mechanics of on-chain order execution and the broader economic incentives that shape mempool activity and liquidity provisioning. For builders and investors, the event emphasizes the value of robust monitoring, greater transparency around routing logic, and the potential benefits of standardized safeguards that reduce the chance of outsized losses in complex transactions.

CoW DAO’s assessment adds nuance to the discussion by pointing to infrastructure gaps, not just liquidity depth. It noted that an outdated gas limit in a solver used by CoW Swap hindered better-priced quotes from being submitted, leaving users with inferior options. A possible mempool leak was also discussed as a contributing factor to the outsized quote that informed the loss. The joint acknowledgment from Aave and CoW DAO that “not all issues are fully resolved” underscores the collaborative path ahead—fixes, audits, and perhaps new safeguards—needed to improve resilience in cross-ecosystem swaps that lean on multiple on-chain participants.

As the ecosystem matures, projects that overlap between lending protocols and decentralized exchanges increasingly rely on layered protections. Aave Shield, if implemented as described, would add a proactive defense rather than a reactive one, potentially reducing users’ exposure to price impact during volatile periods. The broader takeaway is that users must remain vigilant about routing expectations, price impact disclosures, and the liquidity conditions of the venues they choose for substantial trades. The episode serves as a litmus test for how DeFi platforms balance safety features with user autonomy, especially when dealing with high-value, cross-chain liquidity movements.

What to watch next

  • Deployment timeline for Aave Shield and its configurable toggle, with a focus on whether it will be opt-in by default and how users can adjust risk settings.
  • Formal updates from Aave and CoW DAO detailing findings from the incident and any roadmap shifts for liquidity provisioning, solver updates, or mempool protections.
  • Any governance actions or community discussions about routing heuristics, price impact thresholds, and UX warnings on swap interfaces.
  • Further investigations into MEV defense mechanisms and whether new protections integrate with CoW Swap’s routing logic or other DEX aggregators.
  • Monitoring of liquidity depth changes across major stablecoins and DeFi venues during periods of market stress to gauge resilience improvements.

Sources & verification

Aave Shield aims to curb high-impact swaps after a $50 million loss

Aave Shield is designed to block swaps with a price impact above a defined threshold for trades conducted via the Aave interface. The feature, described in a post-mortem by the team, represents an attempt to introduce a guardrail before trades are signed, reducing the likelihood that users are exposed to extreme slippage in low-liquidity scenarios. The proposed guardrail is anchored to a 25% price impact limit and would be activated automatically for standard route options, with the option for users to disable Shield if they accept higher risk channels. The incident that prompted the plan involved a trader who moved USDt to AAVE on CoW Swap and encountered a dramatic discrepancy between expected and actual takedown values, highlighting how quickly liquidity conditions can shift in high-value trades.

The interaction underscores a broader challenge for DeFi—balancing user freedom with protective barriers that do not stifle legitimate, sophisticated trading strategies. While shield features cannot eliminate all forms of risk, they can help prevent traders from signing away too much value in a moment of liquidity stress, potentially safeguarding both retail and institutional participants. The ongoing collaboration between Aave and CoW DAO signals an intent to address root causes—ranging from liquidity provisioning to on-chain quote accuracy and gas-limit governance—that contribute to extreme price disclosures in real-world trades.

Advertisement

As the ecosystem continues to adapt, the industry will watch closely how these protections perform in live markets, especially during periods of volatility. If Aave Shield proves effective, it could set a precedent for more proactive risk controls across DeFi interfaces, encouraging exchanges and aggregators to refine their pricing models and warning systems. For users, the episode reinforces the importance of reading on-screen risk disclosures, understanding the consequences of high-impact routes, and considering the broader liquidity landscape when executing multi-million-dollar swaps.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Source link

Advertisement
Continue Reading

Crypto World

Aave to Roll Out Aave Shield After $50M User Loss Incident

Published

on

Aave to Roll Out Aave Shield After $50M User Loss Incident

Decentralized finance protocol Aave said it is introducing a new feature to block swaps with a price impact above 25% after a user lost $50 million in a trade while interacting with Aave’s interface last week. 

“We are soon deploying a new feature, Aave Shield, which provides more protections for users who use the swap feature in the Aave interface aave.com,” Aave said in a post-mortem statement on Saturday.

Aave said users would need to manually disable the Aave Shield protection feature to proceed with high-risk trades.

The incident occurred on Thursday, when the user went to convert $50.4 million worth of USDt (USDT) for Aave (AAVE) via decentralized exchange CoW Swap, but received only $36,500 worth of Aave due to a lack of liquidity and other infrastructure failures, generating a loss of just over $50 million. 

Advertisement

Part of this loss was also a result of a Maximal Extractable Value (MEV) bot that executed a sandwich attack on the user, profiting nearly $10 million.

User ignored multiple warning signs

Aave said the user signed the transaction despite multiple warnings appearing on the platform’s interface. 

This included alerts about a “high price impact” and a notice stating the route might return less due to low liquidity or small order size. 

The user also ticked a confirmation box stating, “I confirm the swap with a potential 100% value loss,” Aave said. 

Advertisement
What the user would have seen on Aave’s interface before signing the transaction. Source: Aave

Incident shows DeFi still needs work: CoW DAO 

While Aave and CoW DAO, the team behind CoW Swap, said poor liquidity led to the “extreme price impact,” CoW DAO added that multiple infrastructure failures also played a role.

CoW DAO said a solver — a third-party service that finds the best way to do a trade — was affected by an outdated gas limit, which blocked better-priced quotes and left only a much worse option for the user to consider.