Urgent.News

What's breaking now, across thousands of outlets.

Tech

Governance Attack Surface Review: Venus Core Pool

Governance Attack Surface Review: Venus Core Pool Target Protocol : Venus Core Pool (TVL: $1278.3M) Governance Attack Surface Review – Venus Core Pool Protocol: Venus Core Pool (Ethereum & L2) TVL: ≈ $1.28 B (Sep 2026) Prepared by: [Your Firm] – Senior DeFi Security Research & Auditing Team Date: 18 September 2026 1. Executive Summary The Venus Core Pool is a high‑value lending/borrowing market…

Governance Attack Surface Review: Venus Core Pool

The Venus Core Pool protocol, which manages a $1.28 billion TVL across Ethereum and Layer 2 networks, relies on a decentralized governance layer to handle risk parameters, contract upgrades, and treasury fund allocation. Despite multiple audits of the core financial contracts, the governance subsystem has not been thoroughly reviewed since the v2.3 upgrade in March 2025.

This review focuses on the governance flow and its interaction with core contracts, identifying nine distinct attack vectors with a high overall risk rating of 7/10.

The first vector, timelock bypass via re‑entrancy, involves a malicious proposer executing a call through the low‑level call{value: value}(data) function, allowing the attacker to circumvent the 48-hour delay enforced by the timelock controller. This could result in full control of the contracts, leading to a full protocol takeover. The likelihood of such an attack is medium due to the relatively low threshold required to acquire the PROPOSER_ROLE.

The second vector, flash‑loan‑driven voting power inflation, exploits the snapshot mechanism that records token balances at a specific block without locking them. By borrowing a large amount of VRT via a flash loan, an attacker can temporarily inflate their voting power and manipulate parameters during a single transaction. This high likelihood attack, requiring only a well‑funded attacker, can force critical changes to the protocol, such as under‑collateralized borrowing and liquidation attacks.

The third vector, the delegate‑call upgradeability trap, allows an admin address to upgrade core contracts using the delegatecall pattern. If the new implementation contains malicious self‑destruct or storage‑clobbering functions, the admin could irreversibly destroy the proxy or corrupt its storage, leading to loss of funds or permanent market freezing. While the likelihood of successful exploitation is low‑medium, it remains a critical vulnerability due to the current multisig control structure.

The fourth vector, proposal spam leading to governance fatigue, arises from the low barrier to entry for submitting proposals, costing only a modest gas fee. An adversary could flood the proposal queue with low‑value or malicious proposals, causing delays in addressing genuine emergencies and increasing operational overhead. This high likelihood attack has a medium impact due to the potential for a governance freeze if the community stops voting.

The fifth vector, quorum manipulation through token‑locking contracts, targets the quorum requirement of 2% of the total VRT supply. An attacker could use token‑locking contracts to artificially inflate the quorum, enabling parameter changes that could open the pool to under‑collateralized borrowing and liquidation attacks. This attack has a high likelihood and medium impact, as it requires only a sufficient holding of VRT tokens.

The sixth vector, insufficient separation of treasury and protocol admin, stems from the shared multisig control structure for both treasury management and protocol upgrades. If compromised, this could allow an attacker to manipulate treasury funds or execute unauthorized upgrades, leading to significant financial losses or protocol instability.

The seventh vector, governance contract upgrade without multi‑sig review, occurs when the core contracts are upgraded using a delegatecall pattern without requiring multi‑sig approval. This leaves the entire protocol vulnerable to malicious upgrades, resulting in potential loss of user funds or permanent market freeze. The likelihood of this attack is low, but the impact is critical.

Finally, the eighth vector, cross‑chain replay attacks on L2 governance actions, targets the L2 governance implementation, which may not adequately protect against replay attacks on other blockchains. This could allow an attacker to replay transactions on L2, leading to unauthorized actions or fund transfers. With a high likelihood and medium impact, this attack vector underscores the need for improved security measures in L2 governance implementations.

Overall, the Governance Attack Surface Review highlights a high-risk environment within the Venus Core Pool protocol, primarily due to the interplay between governance mechanisms and core contract functionality. The identified vectors present significant threats that could compromise the integrity, security, and stability of the protocol if not properly addressed through targeted remediation steps.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

디지털 교차로: 블록체인 시대의 사이버보안, 데이터 주권, AI 윤리 탐색

디지털의 지평은 인공지능(AI)의 급속한 발전과 블록체인 기술의 변함없는 잠재력에 힘입어 전례 없는 속도로 확장되고 있다. 이러한 진화는 혁신적인 기회를 예고하면서도, 동시에 사이버보안, 데이터 소유권, 그리고 기본적인 프라이버시 권리에 대한 중요한 논쟁을 격화시킨다.

  • Haruko cyber attack exposes supply chain vulnerabilities in crypto institutions
  • AI data scraping raises consent and compensation concerns for vast datasets
  • Algorithmic surveillance by DHS sparks constitutional debates on civil liberties

More from Friday 18 September →