A significant exploit was discovered on the Venus Protocol, a prominent lending platform on the BNB Chain, resulting in the loss of approximately $27 million in assets. According to on-chain analysts, the protocol's Core Pool Comptroller contract was allegedly updated to redirect assets to a malicious address, affecting various tokens including vUSDC and vETH. The security teams are currently monitoring the stolen funds, which remain in the attacker's contract, while the Venus community has not yet released an official statement. Venus Protocol operates as a money market on the BNB Chain, enabling users to deposit assets to earn interest and allowing borrowers to take out loans by posting collateral.

The platform's native token, XVS, plays a crucial role in governance and protocol incentives, with Venus previously holding over $7 billion in assets and serving as a key component of the BNB Chain's DeFi ecosystem.