Venus Protocol, a crypto lending and borrowing platform built on the Binance Smart Chain, has helped a user who lost funds to a phishing attack last week to retrieve the stolen funds. Notably, the funds were worth about $13.5 million at the time of loss. However, due to market fluctuations, the stolen crypto was valued at $11.4 million when it was returned.
After conducting diligence checks, we are happy to share that as of Sep-06-2025 01:33:10 PM UTC, we have officially returned @KuanSun1990‘s positions worth $11.4M at today’s token prices.
Transaction tx linked below.
— Venus Protocol (@VenusProtocol) September 8, 2025
Over $13.5M for the Thief
According to recent reports, the exploit occurred on September 2, 2025. Thereafter, the victim, identified as Kuan Sun, a top trader on the Venus Decentralized Finance (DeFi) platform, took the incident to X, explaining in detail how it transpired. He unknowingly approved a malicious transaction, granting the exploiter access to move funds from his wallet. He noted that it felt like an attack from the famous North Korean hacking group, Lazarus.
[One Night of Horror] How I Almost Lost $13M in the Venus Phishing Attack
People often say there’s nothing sweeter than realizing a disaster was just a scare. But you’ll never understand the weight of those words until you come within inches of losing everything.
On September…
— Kuan Sun (@KuanSun1990) September 4, 2025
Following the incident, the Venus Protocol paused its activities to investigate the exploiter’s actions and attempt to recover the stolen funds. It also conducted examinations and confirmed that the project was secure and not directly affected, blaming the user for his loss.
Phishing Gone Wrong
A few hours after the incident, the Venus team tracked the stolen funds by force-liquidating the hackers’ trade positions. It fully recovered the stolen funds afterwards, leaving the thief with nothing.
Moreover, as revealed on Monday, it has returned the stolen funds to the affected DeFi trader. Marking one of the few cases of a crypto hack recovery.
Another recent case of an exploit recovery involved the decentralized exchange platform GMX, which lost $40 million in July. Following the incident, a 10% bounty was issued to the hacker to return the stolen funds. Within 48 hours, the exploiter traded with the stolen funds and profited from the market. The bad actor returned the stolen crypto afterward, deducting the promised 10%.












