{"id":46967,"date":"2025-09-04T20:54:18","date_gmt":"2025-09-04T13:54:18","guid":{"rendered":"https:\/\/hbbgroup.net\/venus-protocol-recovers-users-13-5m-stolen-in-phishing-attack\/"},"modified":"2025-09-04T20:54:18","modified_gmt":"2025-09-04T13:54:18","slug":"venus-protocol-recovers-users-13-5m-stolen-in-phishing-attack","status":"publish","type":"post","link":"https:\/\/hbbgroup.net\/zh\/venus-protocol-recovers-users-13-5m-stolen-in-phishing-attack\/","title":{"rendered":"Venus Protocol recovers user\u2019s $13.5M stolen in phishing attack"},"content":{"rendered":"<div data-gtm-locator=\"articles\" data-v-43e640e6>\n<article id=\"article-213778\" data-v-43e640e6>\n<p itemprop=\"description\" data-v-43e640e6> Victim Kuan Sun praised Venus and partners after $13.5M recovery, calling it \u201ca battle we actually won\u201d through joint efforts. <\/p>\n<div data-v-43e640e6><picture><source media=\"(min-width: 1200px)\" ><source media=\"(min-width: 992px)\" ><source media=\"(min-width: 768px)\" ><source media=\"(min-width: 480px)\" ><img  loading=\"eager\" fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=1434\/https:\/\/s3.cointelegraph.com\/uploads\/2025-03\/0195be26-e142-7300-b94b-6606b559ff91\" alt=\"Venus Protocol recovers user\u2019s $13.5M stolen in phishing attack\"><\/picture><\/div>\n<div data-v-43e640e6>\n<div data-v-43e640e6>\n<p>Decentralized finance (DeFi) lending platform Venus Protocol helped a user recover stolen crypto following a phishing attack tied to North Korea\u2019s Lazarus Group.\u00a0<\/p>\n<p>On Thursday, Venus Protocol <a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/VenusProtocol\/status\/1963251755543839227\" rel=\"noopener nofollow\" target=\"_blank\" title=\"null\">announced<\/a> that it had helped a user recover $13.5 million in crypto after the <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/defi-trader-loses-27m-phishing-scam-venus-protocol-pauses\" title=\"null\">phishing incident that occurred on Tuesday<\/a>. At the time, Venus Protocol paused the platform as a precautionary measure and began investigating.\u00a0<\/p>\n<p>According to Venus, the pause halted further fund movement, while audits confirmed Venus\u2019 smart contracts and front end were uncompromised.<\/p>\n<h2>Emergency vote enables fund recovery<\/h2>\n<p>An emergency governance vote allowed the forced liquidation of the attacker\u2019s wallet, enabling stolen tokens to be seized and sent to a recovery address.\u00a0<\/p>\n<figure><img decoding=\"async\" alt src=\"https:\/\/s3.cointelegraph.com\/uploads\/2025-09\/019914b6-2552-76d2-a7e9-5274bdb4a4bb\" title><figcaption><em>Source: <\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/KuanSun1990\/status\/1963424876318134294\" rel=\"https:\/\/x.com\/KuanSun1990\/status\/1963424876318134294\" target=\"https:\/\/x.com\/KuanSun1990\/status\/1963424876318134294\" title=\"https:\/\/x.com\/KuanSun1990\/status\/1963424876318134294\"><em>Kuan Sun<\/em><\/a><\/figcaption><\/figure>\n<h2>Attackers exploited a malicious Zoom client<\/h2>\n<p>In the post-mortem, Venus revealed that the attackers used a malicious Zoom client to trick the victim into granting delegated control over the account. <\/p>\n<p>This allowed the perpetrators to borrow and redeem on the victim\u2019s behalf, enabling them to drain millions in stablecoins and wrapped assets.\u00a0<\/p>\n<p>The protocol\u2019s security partners, HExagate and Hypernative, flagged the suspicious transaction within minutes, leading to the decision to pause the protocol. According to Venus, the recovery process unfolded in less than 12 hours.\u00a0<\/p>\n<p>Kuan Sun, who was identified as the victim of the attack, <a data-ct-non-breakable=\"null\" href=\"https:\/\/x.com\/KuanSun1990\/status\/1963424876318134294\" rel=\"noopener nofollow\" target=\"_blank\" title=\"null\">thanked<\/a> the teams behind the recovery. \u201cWhat could have been a total disaster turned into a battle we actually won, thanks to an incredible group of teams,\u201d Sun wrote.<\/p>\n<p>PeckShield, Binance, and SlowMist also assisted in the recovery.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/wlfi-hack-attempts-blacklisting-token-launch\" title=\"null\"><em><strong>WLFI blocks hacking attempts with onchain blacklisting<\/strong><\/em><\/a><\/p>\n<h2>Phishing attack linked to the Lazarus Group<\/h2>\n<p>SlowMist\u2019s analysis linked the attack to the Lazarus Group, a North Korea-backed collective blamed for major crypto heists, including the $600M Ronin bridge exploit and the $1.5B Bybit hack. <\/p>\n<p>Sun said SlowMist carried out extensive analysis work and was \u201camong the very first to point out that Lazarus was behind this attack.\u201d<\/p>\n<p><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/learn\/articles\/lazarus-group-hackers-behind-billion-dollar-heists\" title=\"null\">The Lazarus Group<\/a> is a North Korea-linked hacking collective believed to operate under the country\u2019s intelligence agency. <\/p>\n<p><iframe width=\"100%\" height=\"315\" src=\"https:\/\/www.youtube.com\/embed\/NDv0RfehETQ?start=\" frameborder=\"0\" allow=\"accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen loading=\"lazy\"><\/iframe><\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/magazine\/astrology-could-make-you-better-crypto-trader-heres-why\/\" title=\"null\"><em><strong>Astrology could make you a better crypto trader: It has been foretold<\/strong><\/em><\/a><\/p>\n<p><template data-name=\"subscription_form\" data-type=\"markets_outlook\" data-ct-non-breakable=\"undefined\" label=\"Subscription Form: Markets Outlook\"><\/template><\/div>\n<p><img decoding=\"async\" alt src=\"https:\/\/zoa.cointelegraph.com\/pixel?postId=213778&#038;regionId=1\" data-v-43e640e6><\/p>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Victim Kuan Sun praised Venus and partners after $13.5M recovery, calling it \u201ca battle we actually won\u201d through joint efforts. [&hellip;]<\/p>","protected":false},"author":1,"featured_media":46968,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[220],"tags":[],"class_list":["post-46967","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tien-dien-tu"],"acf":[],"_links":{"self":[{"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/posts\/46967","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/comments?post=46967"}],"version-history":[{"count":0,"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/posts\/46967\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/media\/46968"}],"wp:attachment":[{"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/media?parent=46967"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/categories?post=46967"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hbbgroup.net\/zh\/wp-json\/wp\/v2\/tags?post=46967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}