Venus Core Pool Governance Rated High Risk With Nine Attack Vectors Identified
A security audit of Venus Core Pool, a DeFi lending protocol with approximately $1.28 billion in total value locked, has identified nine distinct governance attack vectors and assigned an overall risk rating of 7 out of 10. The review, dated September 18, 2026, focused on the on-chain governance flow covering proposal creation, voting, execution, and contract upgrades. Among the most critical findings are a flash-loan-driven voting power inflation attack scored 9/10 and a timelock bypass via re-entrancy scored 8/10, both considered technically feasible. Auditors noted that the governance subsystem had not been thoroughly examined since the v2.3 upgrade in March 2025, leaving key administrative functions exposed. The report attributes the elevated risk to a combination of a large treasury, powerful admin controls, and a relatively permissive quorum model that could be exploited by a coordinated or well-funded adversary.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in