Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Anatomy of the Venus Protocol Whale Hack

Anatomy of the Venus Protocol Whale Hack

BeInCrypto2025/09/05 13:17
By: Paul Kim
SUN-0.52%
A crypto whale, Kuan Sun, lost $13.5M in a sophisticated phishing attack that exploited a fake Zoom meeting. Thanks to a quick response, he successfully recovered the funds.

Earlier this week, crypto whale Kuan Sun shared his detailed experience of being targeted by a sophisticated phishing attack on his X account.

This story serves as a stark warning to all investors, as he lost and then recovered $13.5 million. As the digital asset ecosystem expands, so does the risk of hacking. How can investors prevent massive losses?

A Seemingly Harmless Meeting That Became a Nightmare

A phishing attack on Tuesday robbed Kuan Sun, a user of the decentralized lending platform Venus Protocol, of his cryptocurrency. However, thanks to the swift response and cooperation of the Venus Protocol team, he was able to recover the stolen funds.

The elaborate attack began in April 2025 at the Hong Kong Wanxiang Conference. There, a mutual friend introduced Sun to someone who claimed to be a representative for Stack’s Asia Business Development. This kind of networking is common in the crypto space, and they added each other on Telegram.

On August 29, the so-called “BD” requested a simple Zoom meeting. Sun joined late and noticed that there was no sound in the room.

A pop-up message on his webpage read, “Your microphone needs an update.” Confused, Sun clicked the upgrade button—a fatal mistake that set the trap.

Sun later realized the hackers were not acting on the fly. He said the highly customized attack had been in motion since Monday, targeting him specifically.

Anatomy of the Venus Protocol Whale Hack image 0X Post From the Victim

After the “update,” he started seeing strange messages on his computer. The Chrome browser would close abnormally, and a “Restore tabs?” message would pop up.

Suspecting nothing, Sun continued his routine and accessed Venus Protocol through his browser. There, he proceeded to perform a withdrawal, a task he had done countless times before.

Shortly after, his computer slowed down, his Google account was logged out of Chrome, and strange, unfamiliar transactions appeared in his wallet. He immediately knew something was terribly wrong.

The analysis suggests that the hackers replaced his frequently used Rabby wallet extension with a malicious program. This tactic is often used by Lazarus, the notorious North Korean hacking group.

After gaining wallet approval authority, they quickly transferred various tokens, including vUSDC, vETH, vWBETH, and vBNB.

A Swift Recovery and Key Lessons

Sun acted quickly by contacting blockchain security firms Peckshield and Slowmist for guidance. He also reached out to the Venus Protocol team for help.

As a result, Venus Protocol immediately paused the platform as a preventive measure and began an investigation.

They then initiated an emergency governance vote to force-liquidate the attacker’s wallet, allowing Sun to successfully recover his $13.5 million.

On Thursday, Sun shared his story and his key takeaways. He warned that North Korean hackers are increasingly using a combination of social engineering, deepfakes, and Trojans.

As a result, what appears to be a legitimate video conference or a normal Twitter account could be entirely fake.

He specifically advised users to avoid Zoom links from others and to download program plugins only from official channels. He also urged them never to click “upgrade” links that appear in pop-up windows.

Sun expressed his gratitude to the Venus team for their swift action in preventing further damage. He urged everyone to “always be suspicious of any requests you receive in daily life, and always respond calmly.”

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Respect the PUMP: Crypto’s emerging meme season

Crypto is shifting into risk-on mode — pump.fun dominates meme activity, while Lido leans on treasury maneuvers

Blockworks2025/09/14 21:57
Mars Weekly | CARDS market cap surpasses $650 million, reaching a record high; probability of a 50 basis point Fed rate cut in September is 6.6%

Ethereum Foundation has released an end-to-end privacy roadmap, focusing on three main areas: privacy writing, reading, and proof, and plans to launch the experimental L2 PlasmaFold. CARDS market cap hits a record high, and pump.fun's live stream numbers have surpassed Rumble. The Shibarium cross-chain bridge suffered an attack, resulting in a loss of $2.4 million. Summary generated by Mars AI. The accuracy and completeness of this summary generated by the Mars AI model are still in the iterative update stage.

MarsBit2025/09/14 20:20

Trending news

More
1
Respect the PUMP: Crypto’s emerging meme season
2
Bittensor Hits Escape Velocity as Decentralized AI Adoption Accelerates

Crypto prices

More
Bitcoin
Bitcoin
BTC
$115,930.08
+0.03%
Ethereum
Ethereum
ETH
$4,622.47
-0.79%
XRP
XRP
XRP
$3.05
-2.39%
Tether USDt
Tether USDt
USDT
$1
+0.00%
Solana
Solana
SOL
$241.67
+0.16%
BNB
BNB
BNB
$933.63
+0.20%
USDC
USDC
USDC
$1
+0.03%
Dogecoin
Dogecoin
DOGE
$0.2799
-2.88%
TRON
TRON
TRX
$0.3490
-0.25%
Cardano
Cardano
ADA
$0.8911
-4.13%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter