Skip to content
← Back to newsDeFi Community Recovers $13.5M in Swift Action Against Phishing Attack
Security

DeFi Community Recovers $13.5M in Swift Action Against Phishing Attack

By ToTo BugelmanNewcomer0 rep· 9/5/2025

Decentralized finance (DeFi) platform Venus Protocol has successfully recovered $13.5 million in cryptocurrency that was stolen in a sophisticated phishing attack. The incident, which targeted a high-value user, was swiftly addressed through a combination of platform pausing, emergency governance actions, and collaborative efforts from security firms, ultimately preventing further losses and restoring confidence in the protocol.

 

Venus Protocol

 

Key Takeaways

  • Venus Protocol recovered $13.5 million lost in a phishing attack.

  • The attack exploited a malicious Zoom client to trick a user into granting account control.

  • The Lazarus Group, linked to North Korea, is suspected to be behind the attack.

  • An emergency governance vote allowed for the liquidation of the attacker's wallet and recovery of funds.

  • The protocol's smart contracts and front end remained uncompromised.

 

Phishing Attack Details

The attack occurred when a user, identified as Kuan Sun, was tricked by a malicious Zoom client. This allowed attackers to gain delegated control over the user's account, enabling them to borrow and redeem assets on their behalf. Millions in stablecoins and wrapped assets were drained from the user's wallet. While initial estimates placed the loss at $27 million, the final figure was revised to $13.5 million after accounting for the user's outstanding debt.

 

Swift Response and Governance Intervention

Upon detecting the suspicious activity, Venus Protocol immediately paused its platform to halt further fund movement and prevent the attacker from moving or laundering the stolen assets. Security partners HExagate and Hypernative flagged the transactions within minutes, initiating the protocol's response. An emergency governance vote was quickly conducted, leading to a unanimous decision to liquidate the attacker's wallet. This action allowed the stolen tokens to be seized and sent to a recovery address, with the entire recovery process completed in under 12 hours.

 

Kuan Sun

 

Attribution and Collaboration

Analysis by SlowMist linked the phishing attack to the Lazarus Group, a notorious North Korea-backed hacking collective known for orchestrating major crypto heists. The group's modus operandi often involves social engineering tactics to compromise high-value accounts. Several entities, including PeckShield, Binance, and SlowMist, collaborated with Venus Protocol to facilitate the recovery and investigate the incident.

 

Market Impact and Future Implications

The incident initially caused a minor dip in Venus Protocol's native token, XVS, but confidence was quickly restored following the successful recovery. The event highlights the ongoing risks within the DeFi space and the effectiveness of decentralized governance in crisis management. Venus Protocol plans to release a detailed post-mortem report to outline the steps taken during the recovery and security audit.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

DeFi Community Recovers $13.5M in Swift Action Against Phishing Attack | BlockzHub