Venus Core Pool

Orange · 66/100

Executive summary

Venus Core Pool is the primary over-collateralized lending market of Venus Protocol on BNB Chain, scoring 43/100 (orange band) with high data confidence (87/100) but a 10-point penalty for unresolved incident remediation.

  • Security: Multiple audits by CertiK, Quantstamp, OpenZeppelin, Fairyproof, and Hacken since 2021; most recent E-Mode audit (September 2025) found only informational issues; active $250k Immunefi bug bounty; however, bytecode-to-audit match is not verifiable as of September 2026.
  • Incidents: Seven major incidents since 2021 totaling ~$117M in losses, including May 2021 XVS manipulation ($77M), May 2022 LUNA oracle failure ($14.2M), October 2022 BNB bridge exploit ($6.9M), March 2025 zkSync donation attack ($902k), September 2025 user phishing (resolved, $13.5M recovered), October 2025 WBETH depeg ($4.7M, remediation in progress), October 2025 CAKE oracle deviation ($1.1M, remediation in progress), and March 2026 BSC donation attack ($3.7M, resolved with reimbursement); the October 2025 incidents remain incompletely remediated.
  • Governance & custody: Real hybrid governance via XVS token holders through Governor Bravo with 48-hour normal timelock, but AccessControlManager permits guardian multisigs to execute risk-parameter and pause actions outside DAO votes, creating material centralization risk; proposal threshold discrepancy (300k vs. 1M XVS) not verifiable; smart-contract pooled custody with optional institutional Cactus Custody integration.
  • Top risks: Oracle failure (demonstrated by August 2026 lisUSD incident where feed diverged 8.9% for 32 minutes), liquidation shortfall during market stress (history of bad debt), LST/restaking depeg exposure (thin buffers on asBNB/BNB and SolvBTC positions per July 2026 analysis), bridge/wrapped-asset counterparty risk (post-April 2026 rsETH exploit, Venus added bridge requirements but current exposure not verifiable), and privileged governance/emergency-bypass actions via ACM and guardians.
  • Strengths: Established BSC protocol with $1.26B TVL and deep liquidity; efficient BNB Chain economics (low fees, fast finality); robust multi-source ResilientOracle with Chainlink/RedStone/Pyth/Binance feeds plus DeviationSentinel monitoring; risk fund for bad-debt absorption; broad BEP-20 composability; transparent documentation and API; fair-launch XVS tokenomics with no founder pre-mine.
  • Unverified: Current reserve/treasury balances, asset composition, and Core Pool-specific exposure concentration not verifiable; largest collateral asset and stress-test loss estimates not verifiable; exact signer setup and multisig thresholds for guardians not disclosed; live proposal threshold and quorum parameters not confirmed on-chain; primary yield source breakdown and any negative-yield periods not verifiable; bridge exposure by market and current LST buffer levels stale (July 2026) and not independently verified.
  • Recommended exposure: Conservative allocation only, treating as orange-band risk; limit to <5% of portfolio given unresolved October 2025 incidents and repeated oracle/liquidation stress history; prefer stablecoin or major-asset markets with verified multi-source oracles; avoid LST/restaking and low-liquidity collateral until buffer and bridge exposure can be verified; monitor governance proposals for emergency actions and ACM permission changes; require independent confirmation of WBETH and CAKE remediation completion before increasing exposure.
  • Open questions: Verify completion status and user compensation for October 2025 WBETH depeg and CAKE bad-debt incidents; confirm current on-chain proposal threshold, quorum, and guardian multisig signer identities/thresholds; obtain live Dune or on-chain data for top-10 collateral concentration, utilization by asset, and reserve fund balances; verify bytecode match between deployed Core Pool contracts and latest audited commits; clarify ACM permission scope and whether any guardian actions bypass timelock; assess current bridge exposure by market and confirm compliance with April 2026 bridge requirements; determine primary yield source (organic borrow interest vs. XVS incentives) and current subsidy percentage.

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 10 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 50 10.0 last full audit 2025-09-12 is older than a year
Incidents 20% 100 20.0 2 open incident(s), $5,800,000 at risk = 0.5% of TVL (threshold 10%)
Governance 20% 75 15.0 DAO governance; admin withdrawal rights unknown
TVL 20% 7 1.4 TVL $1,263,116,969 = 7% of reference ($17,538,184,136)
Data confidence 87 7/7 critical categories; 18/49 verified facts; 49/49 fresh (180d)

Identification

protocol identification

two sources

Identification

  • Name: Venus Protocol – Core Pool (main lending/borrowing market on BNB Chain).
  • Website: venus.io (confirmed by protocol site and external descriptions).
  • Docs: Current technical docs at docs-v4.venus.io, including contracts overview and Core Pool references.
  • Category: Over‑collateralized money market / lending protocol on BNB Chain.
  • Chains: Core Pool operates on BNB Smart Chain (BSC/BNB Chain) only.
  • Native token: XVS (Venus), governance and incentive token for the protocol on BNB Chain.
  • Launch date (Core Pool on BNB): Not explicitly stated in retrieved sources; Venus protocol itself dates back to 2020–2021, but the exact Core Pool launch block/time is Not verifiable as of 2026‑09‑04. Main contract architecture & addresses (BSC) Docs describe standard Compound‑style components:
  • Comptroller (Core Pool controller): manages listed markets, collateral factors, liquidations, and reward emissions.
  • vTokens (market contracts): interest‑bearing tokens (e.g., vUSDC, vBTC) representing deposits; value accrues via pricePerShare.
  • FlashLoan module specific to Core Pool. Specific BSC contract addresses (Comptroller, vTokens, XVS) are referenced in docs and 3rd‑party dashboards but exact address strings are Not verifiable as of 2026‑09‑04 under current constraints. Explorer “verified contract” status therefore also Not verifiable as of 2026‑09‑04. Fork lineage
  • Venus is explicitly described as a Compound‑style lending protocol on BNB Chain, and its GitHub repo and vToken/comptroller design closely mirror Compound’s architecture. This supports classification as a fork or heavy derivative of Compound Finance on BSC.
  • Documented changes vs upstream include:
  • Integration of BNB Chain‑native assets and a broader collateral set (BNB, BTCB, various stables, alt‑L1s, meme/cex‑linked tokens).
  • Rewards logic for XVS and Venus Prime, plus isolation‑mode style borrowing controls in Core Pool.
  • Additional modules such as FlashLoan for Core Pool and custom interest‑rate controllers (e.g., Adrastia PID‑hybrid controller for Core Pool markets). Audits and security / fork‑risk context
  • Security & audit links are maintained in the docs security section, but which audits cover the modified Core Pool vs original fork is Not verifiable as of 2026‑09‑04.
  • Historical issues: Venus as a Compound‑style fork has had prior risk events (e.g., liquidation and oracle incidents) discussed in media and community, but specific “malicious modification” in Venus Core Pool codebase or in other similar forks is Not verifiable as of 2026‑09‑04 from retrieved data. Contradiction check box
  • TVL for Venus Core Pool is reported around $1.47B in a June 2026 media piece and different figures on aggregators like DefiLlama and APY Hub.
  • Without direct on‑chain querying, the true TVL is Not verifiable as of 2026‑09‑04; discrepancies between aggregators are an explicit risk finding.
Evidence (15)

maturity

two sources

Venus Core Pool on BSC is more than a landing page: Venus maintains a full documentation site with core-pool technical references, deployed-contracts pages, and an API section, which indicates a mature product and developer surface rather than a simple marketing site. The docs also expose pool-level references and callable methods for vault flows such as deposit, requestWithdrawal, and executeWithdrawal, showing that the protocol documents live user actions and not just static information. Open API: yes.

Venus’ docs explicitly state that the API is available without authentication for mainnet and testnet, and they list pool endpoints under the API section. Live deposits/withdrawals: verifiable from the docs as supported actions, but not verifiable as of 2026-09-04 whether the current public web app frontend on BSC is fully functional end-to-end, because no independent web evidence was available here for transaction success, broken-link checks, or live UI state. Not verifiable as of 2026-09-04.

Template/fake-metrics signs: not verifiable as of 2026-09-04. No independent source in this run confirmed broken links, placeholder metrics, or a clone/template site for this specific BSC Venus Core Pool instance.

Evidence (3)

Security

bug bounty

unverified

Venus Core Pool on BSC appears to have an active Immunefi bug bounty program. The available evidence shows a listed maximum bounty of $250,000, and Venus materials reference the Immunefi Bug Bounty Program ($250k). The program was in place by at least 2025-01-06, based on Venus governance documentation referencing it.

Publicly visible results in the gathered sources are not enough to enumerate paid findings or total payouts for Venus specifically; those are Not verifiable as of 2026-09-04.

Active
Yes
Platform
Immunefi
Max payout
$250K
Since
2025-01-06
Evidence (2)

counterparty risks

one source

Venus Core Pool — BNB Chain | as of September 6, 2026 Assessment: Meaningful dependency and counterparty risk remains, concentrated in oracle infrastructure, wrapped/bridged collateral, stablecoins, LSTs/restaking assets, and a small but growing RWA segment.

  • Oracles/manipulation — high: ResilientOracle supports Chainlink, RedStone, Pyth and Binance Oracle, but configuration is asset-specific; some markets may have only one active source. The August 15, 2026 lisUSD incident demonstrates this risk: a single oracle feed printed approximately 8.9% below the DEX price for 32.5 minutes; pivot and fallback were empty. The incident was resolved, but Venus proposed deprecating the market.
  • LST/restaking and depeg risk — high for affected markets: Venus uses correlated-token oracles that may derive value from an on-chain exchange rate or assume 1:1 parity. Failure of redemption, staking contracts, or the underlying issuer can make the oracle price unreliable. July risk analysis identified thin-buffer correlated positions, particularly asBNB/BNB and SolvBTC or xSolvBTC/BTCB; this is stale off-chain data (>7 days) and not on-chain verified.
  • Bridges/wrapped assets — material: Following the April 18, 2026 rsETH/KelpDAO LayerZero exploit, Venus paused or reduced collateral factors for several cross-chain assets and introduced bridge requirements covering verifier diversity, rate limits, audits and circuit breakers. Current market-by-market bridge exposure is Not verifiable as of September 6, 2026.
  • Stablecoins: Core Pool dependence includes USDT, USDC, USDe/sUSDe, FDUSD, DAI, USD1 and others. July’s independent report showed stablecoins at 18.7% of supply and 42% of borrowing; this is stale and not on-chain verified.
  • Custodians/CEX/MM: Cactus Custody provides institutional access, but this is access infrastructure rather than protocol custody. Direct CEX/market-maker exposure is Not verifiable as of September 6, 2026.
  • RWA issuer/SPV: Tokenized equities and XAUm introduce issuer, custodian, redemption, legal-structure and price-feed risks. Reported July exposure was approximately $0.2M, but this is stale and not on-chain verified. Failure scenarios: oracle mispricing → bad debt/liquidations; LST or stablecoin depeg → correlated-loop insolvency; bridge exploit → worthless collateral; RWA issuer/custodian failure → frozen or unrecoverable assets. dependency_failure_active: false (no currently documented active incident; systemic vulnerabilities remain) max_exposure_pct: null — Not verifiable as of September 6, 2026 without Dune/on-chain dependency attribution.
Dependency failure active
No
Evidence (4)

crypto custody

two sources

Custody in Venus Core Pool is organized as smart-contract custody on BNB Chain: users supply assets into Venus lending markets, receive vTokens as their claim, and can redeem those vTokens for the underlying assets on demand. The pool uses a pooled-collateral model, so enabled collateral is shared across the account’s borrow position rather than segregated per loan. For institutional users, Venus also offers an integrated custody route through Cactus Custody/Cactus Link, which keeps assets within the institution’s existing custody and approval workflow while accessing Venus markets.

Withdrawal is not shown as paused in the gathered evidence, and the docs state supplied funds can be withdrawn on demand; however, a chain-level pause status is not verifiable as of 2026-09-06. Segregated assets: false for the Core Pool’s standard lending model; institutionally segregated custody arrangements via Cactus are an access/workflow layer, not segregated protocol reserves.

Segregated assets
No
Evidence (4)

incident

unverified

May 18, 2021 — XVS price/oracle manipulation and liquidation cascade caused approximately $77M of protocol shortfall. Affected: XVS, BTC and ETH markets, suppliers and borrowers. Venus used treasury/distribution XVS, planned reserve allocation and liquidation/risk-control changes to restore the shortfall.

Status: resolved; direct user reimbursement was not documented; recovered_usd: Not verifiable as of 2026-09-06.

Date
2021-05-18
Cause
Oracle manipulation
Loss
$77.0M
Attacker proceeds
$66.0M
Status
resolved
Reimbursed
No
Evidence (1)

incident

unverified

May 12, 2022 — Chainlink LUNA feed suspension left Venus valuing LUNA materially above spot. Attackers supplied inflated LUNA and borrowed other assets before Venus paused the protocol, creating an initial shortfall of approximately $14.2M. Affected: LUNA/UST markets and Core Pool suppliers.

Venus zeroed feeds, off-boarded markets, added monitoring/fallback-feed/failsafe measures, and committed Risk Fund coverage. Status: resolved; direct user reimbursement was not documented; recovered_usd: Not verifiable as of 2026-09-06.

Date
2022-05-12
Cause
Oracle manipulation
Loss
$14.2M
Status
resolved
Reimbursed
No
Evidence (2)

incident

unverified

October 6-7, 2022 — BNB Token Hub bridge exploit collateral was supplied to Venus BSC and used to borrow assets, leaving undercollateralized exposure. Later remediation moved approximately $34.7M of debt to the exploiter account; residual shortfall was estimated at approximately $6.9M. Venus/BNB Chain used forced liquidation, debt migration and Risk Fund measures.

Status: resolved by shortfall remediation; direct user reimbursement was not documented; recovered_usd: Not verifiable as of 2026-09-06.

Date
2022-10-06
Cause
Bridge / third-party collateral failure
Loss
$6.9M
Status
resolved
Reimbursed
No
Evidence (2)

incident

two sources

A separate Venus-related 2023 BSC event in the search results was not a Core Pool exploit; sources described it as an isolated snBNB pool oracle/pricing issue affecting a limited pool, with temporary pauses and treasury liquidity support. Because it does not cleanly map to Venus Core Pool, it is only a contextual adjacent incident.

Date
2023-12-10
Cause
Oracle manipulation
Loss
$200K
Evidence (2)

incident

one source

Venus Core Pool: Token & Share Accounting via Donation Attack on zkSync Era; loss $902,000 (DeFiLlama hacks registry).

Date
2025-03-29
Cause
Smart-contract exploit
Loss
$902K
Status
status unknown
Classification
Token & Share Accounting
Technique
Donation Attack
Evidence (1)

incident

two sources

September 2, 2025 — A Venus user’s BSC Core Pool position was compromised through phishing/social engineering and malicious delegate approval; Venus contracts were not exploited. Approximately $13.5M of user assets were at risk/drained, while an initial $27M figure included the attacker’s debt position. Affected: one large Venus user/account.

Venus paused markets, passed an emergency governance vote, and force-liquidated/recovered the position. Status: resolved; users reimbursed/recovered through forced liquidation.

Date
2025-09-02
Cause
Key compromise
Loss
$13.5M
Status
resolved
Recovered
$13.5M
Reimbursed
Yes
Evidence (2)

incident

one source

October 10, 2025 — WBETH oracle depeg caused erroneous liquidations between 21:43 and 23:30 UTC. Chaos Labs identified 49 affected users; proposed compensation was collateral seized minus debt repaid, estimated at approximately $4.71M. Compensation was planned in USDT, but later evidence showed 27 of 49 wallets compensated in the first two waves.

Full completion: Not verifiable as of 2026-09-06. Status: remediation_in_progress.

Date
2025-10-10
Cause
Depeg / collateral
Loss
$4.7M
Status
remediation in progress
Evidence (2)

incident

one source

October 10, 2025 — CAKE oracle deviation during the BNB Chain market crash allowed borrowing arbitrage and created approximately $1.1M of BNB Core Pool bad debt; the wider multi-chain event was approximately $1.38M. Affected: CAKE suppliers/borrowers and Core Pool liquidity. Venus proposed Risk Fund repayment, repayment-by-proxy and oracle/risk-parameter improvements.

Suppliers were intended to regain full liquidity. Completion of repayment: Not verifiable as of 2026-09-06. Status: remediation_in_progress.

Date
2025-10-10
Cause
Oracle manipulation
Loss
$1.1M
Status
remediation in progress
Reimbursed
No
Evidence (2)

incident

two sources

Venus Core Pool: Token & Share Accounting via Donation Attack on BSC; loss $3,700,000 (DeFiLlama hacks registry). Remediation status: resolved (retained evidence).

Date
2026-03-15
Cause
Smart-contract exploit
Loss
$3.7M
Attacker proceeds
$14.9M
Status
resolved
Reimbursed
Yes
Classification
Token & Share Accounting
Technique
Donation Attack
Evidence (4)

key management

unverified

Venus Core Pool’s key management is organized as a governance + contract-control model, not as an externally held admin key system. The Core Pool comptroller is the central policy contract: it lists markets, manages positions and liquidations, and exposes setters for risk parameters such as collateral factor, close factor, and liquidation incentive. On BNB Chain, Venus also uses AccessControlManager-style control for sensitive actions; for example, market unlisting is governed by access control and requires multiple preconditions, including pausing all actions, zero borrow/supply caps, and zero collateral factor.

Operational custody is further split from policy control. Venus documents that RiskFundV2 is the current BNB Chain custody contract for protocol-income reserves, and using those funds for bad debt is not automatic; it requires a scope-specific governance or operational action. This indicates that reserve access is intentionally separated from day-to-day lending logic.

In practice, key management appears to rely on on-chain governance and role-scoped permissions for privileged actions, with contract-level guards rather than a single hot wallet controlling the pool. However, the exact signer setup, multisig threshold, and whether any emergency keys exist for the Core Pool are Not verifiable as of 2026-09-04 from the provided sources.

Evidence (2)

smart-contract

two sources

Assessment — Venus Core Pool (BNB Chain), as of September 6, 2026 Architecture / addresses. Core Pool users interact with the Unitroller comptroller proxy (0xfd36e2c2a6789db23113685031d7f16329158384), whose implementation is a diamond-style contract. The diamond maps function selectors to facets and forwards calls with delegatecall; documented facets include Policy, Setter, Market, and Reward. diamondCut changes facet mappings and is admin-controlled. ``text User → vToken markets → Unitroller proxy ↓ delegatecall Diamond comptroller ┌ Policy ─ Setter ─ Market ─ Reward ┐ └ risk params, pause, exits, rewards ┘ ↑ Governance / AccessControlManager ↑ Normal Timelock 0x939b…6396 | FastTrack 0x555b…ce02 Critical Timelock 0x213c…606d | ACM 0x4788…3555 ↓ ResilientOracle 0x6592…ab8A → Chainlink/RedStone/Binance/Pyth `` Administrative control. Venus lists three BNB Chain timelocks, an Access Control Manager, and separate guardians for critical risk parameters, pause/resume, and oracles. The ACM grants granular permissions by contract/function; oracle administrators can configure feeds, bounds, supported assets, and pause state. Upgradeability. Upgradeable: confirmed. The comptroller combines Unitroller proxy upgradeability with diamond facet replacement.

Venus’ oracle contracts are also documented as transparent-proxy implementations; BscScan identifies a Venus deployment as TransparentUpgradeableProxy. Exit / emergency risk. The Market facet handles market entry/exit, while comptroller and oracle actions can be paused globally or per market. Whether users can always redeem/withdraw during each emergency state is Not verifiable as of September 6, 2026. On-chain timelock delay, proxy-admin type, current role holders, renounced roles, and Dune-decoded admin events are Not verifiable as of September 6, 2026 because Dune is unavailable. Worst case. Compromised governance/privileged keys could replace facets, alter collateral/liquidation parameters, manipulate oracle configuration, or freeze activity.

Direct administrative draining of user funds is Not verifiable as of September 6, 2026; do not assume it is impossible. Audit status. OpenZeppelin’s oracle audit reported 0 critical and 0 high issues for its 2023 oracle scope, but this does not certify the current full deployment. Finding: material governance, upgrade, oracle, and freeze risk; not a fully renounced/trustless deployment.

Upgradeable
Yes
Evidence (6)

audit

one source

Venus Protocol (including the Venus Core Pool on BSC) has been audited multiple times by CertiK. One prominent audit is the "Venus v2 Smart Contract Audit" published by CertiK in 2021, covering the core lending/borrowing contracts on Binance Smart Chain (Comptroller, vToken markets, interest rate models, price oracle integration, and protocol parameters). The audit report is hosted on CertiK’s site with a detailed list of issues and their status at the time of the audit.

Whether the exact deployed mainnet bytecode of the current Venus Core Pool contracts still matches the audited versions is Not verifiable as of 2026-09-03.

Auditor
CertiK
Report date
2021-05-27
Scope
Core Venus lending markets on BSC (Comptroller, vTokens, interest rate models, risk parameters, pause/guardian controls, and oracle interaction) as part of the Venus v2 smart contracts.
Findings
The 2021 CertiK audit identified several issues across severities (including at least Medium and Low/Informational), with no outstanding Critical severity issues reported at publication. Some issues related to liquidation incentives, oracle assumptions, and parameterization of risk settings. All higher-severity issues noted in the public report were either fixed or acknowledged with rationale by the Venus team at the time of that audit. Exact counts by severity for the specific Core Pool contracts are not reliably extractable from public summaries and are Not verifiable as of 2026-09-03.
Fix status
According to CertiK’s report, issues of higher severity were marked as "Fixed" or "Acknowledged" by the development team as of the audit’s completion date, with recommended code changes incorporated into updated contracts before or shortly after deployment. Subsequent protocol incidents (e.g., 2021 liquidations/oracle events) led to later code and parameter updates, but a complete, current bytecode-to-audit match for the live Venus Core Pool contracts is Not verifiable as of 2026-09-03.
Evidence (1)

audit

unverified

A second CertiK report is referenced on the Venus security page for 2024-12-26 covering a Pendle oracle update. The exact severity breakdown, fix status, and whether all deployed code was covered are not verifiable from the provided search result.

Auditor
CertiK
Report date
2024-12-26
Scope
Pendle Oracle Update / Resilient Oracle changes; linked on Venus security page
Evidence (1)

audit

unverified

Protocol security page lists a CertiK audit report dated 2025-09-19 for E-Mode support in the Core pool on BNB Chain. The same page also references prior Core pool upgrade-related audit coverage, including the Comptroller upgrade/forced liquidations feature and earlier scope for isolated-pool compatibility. The exact severity breakdown and fix status are not verifiable from the provided search result.

Auditor
CertiK
Report date
2025-09-19
Scope
E-Mode support in the Core pool on BNB Chain; related Core pool upgrade coverage also referenced on the security page
Evidence (1)

audit

one source

Corrected prior record: Quantstamp E-Mode report publication/finalization date should be 2025-09-12 rather than 2025-09-04. The report records an initial report on 2025-09-05 and a final report on 2025-09-12; it found one informational issue, VENE-1, acknowledged by the client. The report’s fix review states the suggestions were addressed.

Bytecode match to currently deployed Core Pool contracts remains unverified.

Auditor
Quantstamp
Report date
2025-09-12
Scope
Diff audit of Venus Protocol E-Mode changes, primarily Core Pool Comptroller Diamond changes, based on commit ce3eb96 / repository commit 174670c.
Findings
0 critical, 0 high, 0 medium; 1 informational finding (VENE-1: mismatched function name), acknowledged.
Fix status
Acknowledged; fix review dated 2025-09-09 states the suggestions were addressed and additional E-Mode testing was added.
Report url
https://certificate.quantstamp.com/full/e-mode-core-pool-venus/6e476cd9-4dd6-4df2-b2d1-b668e1b5c4ea/index.html
Report id
doc:42c6f705d25f845f
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Venus initial audit

Auditor
Fairyproof
Report date
2021-11-16
Scope
BSC Venus contracts, including Comptroller, ComptrollerG4, VAI, interest-rate and governance contracts.
Findings
0 critical, 0 high, 0 medium; 2 low; informational findings were reported as resolved.
Fix status
Critical/high/medium resolved; low findings remained unresolved in the published summary.
Evidence (1)

audit

one source

Venus Automatic Allocation

Auditor
Fairyproof
Report date
2023-08-03
Scope
Automatic income allocation, including Core Pool VToken interest-reserve changes under venus-protocol PR #262.
Findings
Not verifiable as of 2026-09-05.
Fix status
Published report states “Passed”; detailed severity/status extraction is not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Risk Oracle Integration and CorePool Comptroller Interface Change

Auditor
Fairyproof
Report date
2025-02-24
Scope
RiskSteward contracts plus Core Pool Comptroller MarketFacet, PolicyFacet and SetterFacet changes.
Findings
Not verifiable as of 2026-09-05.
Fix status
Not verifiable as of 2026-09-05.
Evidence (1)

audit

one source

Time-Based contracts / Venus protocol audit. The report snippet states the audit covered multiple VenusProtocol PRs touching isolated-pools, venus-protocol, and oracle repos; it found 1 high and 1 low, and says the Venus team fixed all issues.

Auditor
Fairyproof Security Team
Report date
2024-03-04
Scope
Venus Time-Based App; multi-repo changes including isolated-pools, venus-protocol, and oracle PRs.[14]
Findings
1 high, 1 low; 0 critical, 0 medium reported in the snippet.[14]
Fix status
All issues fixed.[14]
Evidence (1)

audit

one source

Risk Oracle Integration and CorePool Comptroller Interface Changing audit. The report says the scope included Venus’s RiskOracle integration and CorePool Comptroller interface changes; it found 2 low-severity issues and states the team fixed both.

Auditor
Fairyproof Security Team
Report date
2025-02-26
Scope
RiskOracle integration and CorePool Comptroller interface changing, tied to Venus governance / venus-protocol pull requests.[8]
Findings
2 low; 0 critical, 0 high, 0 medium reported on the summary snippet.[8]
Fix status
Both issues fixed; report states the Venus team fixed two low-severity issues.[8]
Evidence (1)

audit

unverified

Audit of Venus lending platform smart contracts; report states 0 critical, 1 high, 2 medium, 3 low findings. Findings listed as F-2023-0792 Missing Swap Path Validation (high, fixed), F-2023-0794 Unverifiable Logic (medium, mitigated), F-2023-0793 Mishandled Edge Case (medium, fixed), F-2023-0797 Redundant Check (low, fixed), F-2023-0796 Boolean Equality (low, fixed), F-2023-0795 Missing Zero Address Validation (low, fixed), plus observations I-2023-0202, I-2023-0201, I-2023-0200, I-2023-0199. The public page says 5 issues were addressed and resolved; one observation remained unfixed.

Auditor
Hacken
Report date
2023-06-28
Scope
Venus lending platform / Venus Core Pool smart contract code review; BNB Chain lending platform scope on Hacken page
Evidence (2)

audit

unverified

Audit of VenusProtocol/oracle at commit 78b1a41; the report lists 17 total issues with 0 critical and 0 high severity issues, plus 8 resolved and 2 partially resolved. The issue list shown is dominated by low-severity and informational items.

Auditor
OpenZeppelin
Report date
2023-06-13
Scope
Venus Protocol oracles repository; Oracle system used by Venus on BNB Chain
Evidence (2)

audit

one source

Venus Protocol Diamond Comptroller Audit

Auditor
OpenZeppelin
Report date
2023-08-28
Scope
Comptroller Diamond migration: storage, Diamond, MarketFacet, PolicyFacet, RewardFacet, SetterFacet, XVSRewardsHelper and interfaces.
Findings
0 critical, 0 high, 0 medium; 6 low; 10 informational/code-quality notes.
Fix status
12/16 issues resolved, 1 partially resolved; at least 1 low-severity issue acknowledged and unresolved.
Evidence (1)

audit

one source

Migration Core

Auditor
Quantstamp
Report date
2025-08-29
Scope
Migration of Core Pool Solidity 0.5.x contracts to Solidity 0.8.25, including Comptroller, VTokens, VAI, Liquidator, Oracle and SwapRouter components.
Findings
0 critical reported; 1 informational finding concerning low test coverage, acknowledged.
Fix status
Fix review dated 2025-09-12 states MIG-1 remediated.
Evidence (1)

audit

one source

E-mode Core Pool

Auditor
Quantstamp
Report date
2025-09-04
Scope
PR #614: E-mode changes to the Core Pool Comptroller Diamond and related lending, liquidation and lens contracts.
Findings
0 critical, 0 high, 0 medium; 1 informational finding concerning timestamp dependence, marked acknowledged.
Fix status
Acknowledged; no severe issues reported.
Evidence (1)

Team & Reputation

founders

two sources

Venus Core Pool on BNB Chain is part of Venus Protocol, originally created by the Swipe development team led by founder Joselito Lizarondo, and more recently fronted by Brad Harrison (Head of Venus Labs) and other named contributors, indicating a predominantly public, non‑anon team. ### Founders & Key People

  • Origin / initial founder: Multiple sources state Venus Protocol was “designed and created” by the Swipe project development team under the direction of Joselito Lizarondo, founder of Swipe.
  • Current product leadership: CoinDesk’s Consensus speaker profile lists Brad Harrison, Head of Venus Labs, described as “the product development team behind Venus Protocol.”
  • Business development: A 2026 Venus announcement quotes “Leon, Head of BD, Venus Protocol,” suggesting a broader named leadership group. ### Team structure, public vs. anon
  • Early design: Implemented by Swipe (a centralized crypto card issuer) with a known corporate team.
  • Token economics: Multiple sources emphasize XVS as a “fair launch” token with no founder/team allocations or pre‑mine, implying protocol control via token holders rather than a single controlling founder team.
  • Governance: Control is described as delegated to XVS community holders, with numerous proposals and upgrades coming through governance.
  • Reality check: While not all contributors are named, the presence of public figures (Lizarondo, Harrison, Leon) and conference participation indicates non‑anonymous core leadership rather than a fully pseudonymous DeFi project. ### Corporate setup, office, jurisdiction
  • Initial corporate anchor: Built by Swipe, a global crypto card company historically associated with Binance; this implies a more traditional corporate backdrop, though specific registered entities for Venus Protocol itself are not clearly documented in retrieved data.
  • Current entity / offices: No reliable, protocol‑specific corporate registry, physical office address, or jurisdiction for Venus Labs / Venus Protocol is surfaced in independent sources. The multi‑country office list found at a “venus.ai” site clearly refers to a different AI company, not the DeFi protocol.
  • Name‑collision risk: “Venus AI” is an unrelated business; its offices must not be attributed to Venus Protocol.
  • Onshore vs. offshore: Not verifiable as of 2026‑09‑04; public material does not state where Venus Labs or any Venus legal entity is incorporated. ### Track record, prior projects & incidents
  • Prior project: Swipe itself is a major prior project; Venus was spun out of that development stack.
  • Hacks / incidents: This query set did not surface specific exploit histories or regulatory actions; full risk workup would require dedicated incident search and on‑chain analysis, which is Not verifiable as of 2026‑09‑04 under current tool limits. Reality check:
  • Public, conference‑visible leadership and origin at Swipe support real-business, real-team status.
  • Lack of clear, independent corporate filings or office disclosure leaves jurisdiction, legal entity, and regulatory posture unverified.
  • Governance and “fair launch” design reduce direct founder control but complicate accountability, relevant for institutional risk.
Evidence (8)

general reputation

two sources

Venus Core Pool on BNB Chain has a mixed but generally *established* reputation: it is a long-running, major BSC lending protocol, but its history includes repeated oracle/manipulation and liquidation stress events, which remain the main unresolved concern. Public coverage also points to at least one later suspicious-activity episode in 2025/2026 involving the protocol’s Core Pool, showing that operational risk is still a live issue rather than purely historical. On identity and leadership, available sources consistently tie the protocol to Venus / Venus Protocol on BNB Chain and mention founder Joselito Lizarondo; one report also references Brad Harrison as Head of Venus Labs.

I did not find independently verifiable evidence in the gathered sources for the full founder/investor roster, so those details are *Not verifiable as of 2026-09-04*. On audits and security, Venus claims a substantial audit record, including “over 80 completed audits” and a dedicated security/audits page; another third-party risk page also lists audits from CertiK, PeckShield, and OpenZeppelin, but that page is itself an aggregator-style assessment rather than primary evidence. The protocol’s own claims about audit count should be treated as *unverified marketing claim* unless corroborated by independent audit archives.

Criticisms and adverse events are the main reputational drag. Reporting in 2021 described roughly $200 million in liquidations tied to possible price manipulation of XVS, and another report said the team was allegedly behind or associated with a major exploit narrative; in December 2023, Venus publicly denied a full protocol exploit and said the incident was limited to an oracle/pricing issue affecting borrows of about $200,000. In 2023, Venus also liquidated a large hacker-linked position, which reinforced both its usefulness and its exposure to market stress.

For legal/regulatory issues and sanctions, I found no confirmed sanctions designations or formal regulator/court actions in the gathered sources. *Not verifiable as of 2026-09-04*. Overall sentiment is cautious-neutral: Venus is seen as a mature, important BSC lending venue, but one with a recurring track record of oracle, collateral, and liquidation controversies that keep insolvency/operational-risk concerns alive.

Evidence (8)

Economy

TVL: $1.3B

model

one source

Assessment — Venus Core Pool (BNB Chain)

  • Strategy / assets: Overcollateralized money-market lending. Users supply supported cryptoassets; borrowers draw assets against collateral, while liquidators seize collateral from undercollateralized accounts. Interest rates are algorithmic and utilization-sensitive, with a jump-rate curve.
  • Yield source: Primarily borrower interest passed to suppliers, less the reserve factor; liquidation incentives and any governance-token rewards are secondary. The supply rate depends on cash, borrows, reserves, reserve factor, and bad debt.
  • Organic vs subsidized: Mostly organic lending yield, but current Core Pool incentive composition is Not verifiable as of September 6, 2026. Therefore organic_yield_pct = null.
  • Risk profile: Not market-neutral. Suppliers face liquidity, oracle, bad-debt, and directional collateral/asset-price risk. No evidence of mandatory restaking or an external yield strategy; exposure is to listed money-market assets and borrower credit/liquidation outcomes. User-directed looping/leverage is possible through repeated supply/borrow transactions, but pool-wide leverage is Not verifiable as of September 6, 2026; leverage_ratio = null.
  • Withdrawals / lock-ups: No fixed maturity is indicated. Withdrawals are subject to available market cash; near-100% utilization can prevent full withdrawal until borrowers repay. Markets can also be paused and governed with supply/borrow caps. Specific current caps, gates, and withdrawal fees are Not verifiable as of September 6, 2026.
  • Collateral / liquidation: Market-specific collateral factors, liquidation thresholds, close factors, incentives, and oracle controls apply. Liquidations seize collateral to repay debt.
  • TVL / trend: DeFiLlama reports Venus aggregate TVL of approximately $1.289B, with $1.284B on BSC (~99.6%) and 30-day TVL growth of 20.7%. This is aggregate Venus, not Core Pool-only; product-level Core Pool TVL and a Dune-vs-DeFiLlama comparison are Not verifiable as of September 6, 2026.
  • Revenue / APY: DeFiLlama reports aggregate Venus 30-day fees of about $1.05M and protocol revenue of about $360K; Core Pool-only revenue is Not verifiable as of September 6, 2026. APY history, volatility, and sustainability are Not verifiable as of September 6, 2026; current rates are utilization- and market-specific. Contradiction / limitation: DeFiLlama figures cover the combined Venus deployment, while the requested product is BSC Core Pool; they must not be treated as Core Pool-specific.
Evidence (4)

reserves

one source

As of September 6, 2026, a Core Pool-specific reserve/treasury balance, treasury wallet address, asset-level composition, and current custody balances are Not verifiable as of September 6, 2026. Dune MCP was unavailable for this run; therefore no Dune query ID/execution ID or on-chain balance claim is provided. Scope distinction: Venus Core Pool market reserves are not the same as the protocol treasury. The reserve contract design records balances by comptroller × asset × schema, with separate PROTOCOL_RESERVES and ADDITIONAL_REVENUE buckets, and supports governance/access-controlled distribution targets.

This indicates smart-contract custody and governance-controlled release policy, but not a disclosed current USD balance. Treasury size/composition: DeFiLlama currently reports a protocol-wide Venus treasury of $22.84M: $6.39M majors, $1.78M stablecoins, $0.96M own tokens, and $13.71M other assets. This is an analytics-platform figure, not a Core Pool reserve figure and not independently verified on-chain here. Addresses/custody/control: The reviewed governance material references a Venus Treasury on BNB Chain and lists six buyback-contract destinations—BTCB, ETH, XVS, USDT, USDC and U—but does not expose a clearly identified treasury wallet address in the fetched text. The proposed cleanup routes legacy balances through those contracts; governance parameters and permissions remain unchanged. Reserve policy/evidence: June 2026 reporting states Core Pool borrowers paid $776K gross interest and the protocol retained $133K, a 17.1% blended reserve factor; this is income retained, not reserve assets held.

The same report lists $365.1M Core Pool debt as of June 30, 2026, now stale under the seven-day freshness rule. No reserve attestation was identified. Not verifiable as of September 6, 2026. Contradiction / scope warning: DeFiLlama’s $22.84M treasury and $438.99M active-loans figures are protocol-wide analytics, while Core Pool figures are market-specific; they must not be presented as Core Pool reserves or liabilities.

Evidence (4)

tokenomics

two sources

Venus Core Pool is the main money market of Venus Protocol on BNB Chain; its native token is XVS. Basic token data

  • Token name/ticker: Venus / XVS.
  • Chain: BNB Chain (BEP-20).
  • Main contract address (XVS): 0xCf6BB5389c92Bdda8a3747Ddb454cB7a64626C63 on BSC.
  • Total supply: 30,000,000 XVS fixed cap.
  • Circulating supply / market cap / FDV: values depend on price feeds from analytics sites and are Not verifiable as of [2026-09-04] under the given rules. Token utility and governance role
  • XVS is the governance token of Venus: holders can propose and vote on protocol changes, risk parameters and markets via Venus Governance (voting with XVS).
  • Venus Core Pool uses XVS mainly as collateral and for incentive rewards (liquidity mining) to suppliers/borrowers in certain markets. Revenue share, buybacks, burns, staking
  • Protocol revenue (reserve factor interest and liquidation fees) accrues to the Venus Protocol reserves; XVS itself does not natively receive direct revenue share like a fee rebate token.
  • Venus has implemented XVS buyback and burn mechanisms via governance for risk fund and peg maintenance of VAI; however, exact current parameters and volumes are Not verifiable as of [2026-09-04].
  • XVS “staking” is implemented via Venus Prime / governance staking and reward programs, but yield levels, schedules and live APRs are Not verifiable as of [2026-09-04]. Emissions, unlocks, allocations
  • XVS has no further inflation beyond the 30M cap; remaining emissions are from allocated but unvested or programmatic distributions.
  • Original distribution: fair launch, with allocations to liquidity mining, community grants, reserves, and team, but detailed percentages are inconsistently documented across sources and therefore Not verifiable as of [2026-09-04].
  • Any unlock schedules (team/investors) and whether unlocks executed on-chain are Not verifiable as of [2026-09-04]. Holder concentration and controls
  • Up-to-date top-holder concentration, insider wallets, and treasury balances for XVS on BSC are Not verifiable as of [2026-09-04].
  • Whether the XVS token contract has mint, blacklist, or fee-switch functions and who controls them is Not verifiable as of [2026-09-04]; common references describe XVS as a fixed-supply governance token. DEX liquidity and listings
  • XVS is primarily traded on BNB Chain DEXs (e.g., PancakeSwap) and centralized exchanges; exact current liquidity depth and venue breakdown are Not verifiable as of [2026-09-04].
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin drop below $10,000 would be a severe stress event for Venus Core Pool on BSC, but the exact protocol loss, liquidations, or bad debt outcome is Not verifiable as of 2026-09-04 without on-chain position data and current risk parameters. Venus states that when a borrow becomes insolvent it may be liquidated, that liquidations in the Core Pool occur once an account is under-collateralized, and that the pool uses liquidation thresholds/collateral factors plus a risk fund to absorb shortfalls if they occur. What can be said with confidence is the mechanism of failure mode: if BTC is used as collateral, a collapse to below $10k would likely push many positions below their liquidation threshold, triggering liquidations; if BTC is borrowed against other collateral, the BTC debt side would become easier to repay but would not by itself create a loss event unless correlated collateral also falls.

Venus also explicitly notes that liquidations are partial, capped by close factor, and that seized collateral is split between liquidator and treasury, which can reduce but not eliminate bad-debt risk in a fast-moving crash. The main limiting factor is exposure concentration: whether this stress becomes protocol-threatening depends on how much BTC-linked collateral and debt is outstanding in Core Pool, how much of that is already near threshold, and whether liquidator capacity is sufficient during a gap move. Venus has previously discussed using backstop liquidity and a risk fund to address cascading liquidations and shortfalls, which suggests the protocol is designed to withstand stress, but that is not a guarantee under a move of this magnitude.

So the practical answer is: high liquidation pressure, elevated bad-debt risk, and possible treasury/risk-fund drawdown, but the size of the hit is Not verifiable as of 2026-09-04 from the provided sources alone.

Evidence (5)

stress scenario - largest collateral depegs 20%,

unverified

For Venus Core Pool on BSC, a 20% depeg of the largest collateral is not verifiable as of 2026-09-04 from the provided sources because the available results do not identify the current largest collateral asset or provide on-chain account-level exposure data. The protocol docs confirm that Venus uses collateral factors, liquidation thresholds, and partial liquidations, but they do not supply the live portfolio needed to quantify losses under a specific depeg shock. What can be stated is that Venus liquidations are generally partial rather than full: the protocol caps how much can be repaid in a single liquidation, typically up to 50%, and liquidators receive an incentive on seized collateral.

That means a 20% price shock would first create undercollateralization for accounts heavily concentrated in the depegged asset, but the resulting bad debt, liquidations, and any protocol shortfall depend on the actual borrow/supply composition and the market’s collateral factor, none of which are verifiable here. The only source in the set that discusses a concrete stress scenario is a Chaos Labs parameter note, but it is about BUSD deprecation and collateral-factor changes, not a 20% depeg stress test for the current largest collateral on Venus Core Pool. Therefore the requested stress loss estimate cannot be responsibly calculated from these sources alone. Not verifiable as of 2026-09-04: largest collateral in Venus Core Pool on BSC, its share of pool exposure, and the resulting liquidation/bad-debt amount under a 20% depeg.

Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For Venus Core Pool on BSC, the counterparty-insolvency loss path is: borrower collateral falls below debt value, liquidation is triggered, and any residual shortfall becomes bad debt / insolvency in the pool. If the account is small enough, healAccount(address) can seize all collateral, write off the unpaid remainder as bad debt, and stop interest accrual on that bad debt; otherwise liquidateBorrow handles standard partial liquidations, with seized collateral split between the liquidator and treasury. Who absorbs it: Venus states that each pool has a risk fund funded from pool income in USDT, intended to cover insolvency and bad debt; if bad debt remains, the risk fund reserve is auctioned to recover it. In the Core pool specifically, Venus also notes that bad debt is *not tracked automatically* at the market level, so the accounting/offset path is not fully automated there. Compensation / recovery path: The first compensating layer is the liquidator, who receives a liquidation incentive (seized collateral minus protocol share).

If liquidation leaves bad debt, the risk fund is the next absorber; Venus describes auctioning the reserve or using the insurance/risk fund to cover the shortfall, and community materials say the DAO may also refinance shortfalls through debt mechanisms or grants/XVS in some cases. If there is no liquidator for a bankruptcy address, the insurance fund can take over and compensate for the loss. Smart-contract impact path: the failure flows through the liquidation contracts first, then into the shortfall-handling layer. The documented sequence is: undercollateralized account -> Liquidator / liquidateAccount / healAccount -> bad debt recorded -> Shortfall / risk fund auction or reserve drawdown -> treasury / insurance accounting.

The precise Core-pool implementation details for every fallback branch are Not verifiable as of 2026-09-04 from the available sources, but the documented control path above is the intended mechanism.

Evidence (6)

stress scenario - committed fraud by the DAO or owners

two sources

For a DAO/owner committed-fraud stress scenario on Venus Core Pool (BSC), the relevant loss mode is privileged-contract abuse or governance compromise, not ordinary market risk. I found no direct evidence in the provided sources that Venus DAO or owners actually committed fraud; therefore the scenario is Not verifiable as of 2026-09-04. What is verifiable is that Venus has had incidents consistent with controller/contract compromise and admin/privilege sensitivity: reporting on a 2025 BNB Chain incident says the Core Pool comptroller was suspected to have been updated to a malicious address and assets were siphoned, while documentation and audits confirm the Core Pool has privileged mechanisms and admin-sensitive flows.

For stress purposes, a credible DAO/owner-fraud assumption on BSC would be:

  • Immediate TVL impairment from unauthorized withdrawals of core-pool assets or forced transfers to attacker-controlled addresses. This would be an on-chain expropriation event rather than a price-oracle event.
  • Rapid loss of user confidence and withdrawal pressure, with secondary effects on Venus markets and collateral quality. This is an inference from the privileged-controller nature of the protocol and past incident reporting.
  • Potential bad debt if assets are removed before liquidations or if the protocol’s liquidation and recovery machinery cannot keep pace. The protocol’s own technical docs acknowledge bad-debt handling in accounts and liquidation-related settlement flows. I cannot verify a fraud-loss amount, perpetrator identity, or recovered/irrecoverable balance from the provided sources. The safest risk posture is to model full loss of the affected Core Pool balances on BSC until independently disproven. If you need, I can turn this into a concise risk template with severity, transmission channels, and likely market impact.
Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

For Venus Core Pool on BSC, the primary yield source is not clearly verifiable from the provided sources, and a negative 30d yield for the pool is not supported by the search results. The strongest directly relevant data points show positive or flat 30d APY snapshots for several Core Pool assets, such as USDT, USDC, FDUSD, and BUSD on Barker Money, and a 30d average of 2.63% for Venus Core Pool USDC on DeFi Terminal. DeFiLlama shows an average APY of 0.41% for Venus Core Pool, but it does not break out the primary yield source or establish a negative 30d primary yield.

Under the evidence available here, the correct stress-scenario answer is: Not verifiable as of 2026-09-04. A negative 30d primary yield would need on-chain or protocol-level rate data plus the underlying reward/subsidy accounting, which is not present in the supplied web results. What can be said with confidence is that Venus Core Pool yield is described as coming from borrow interest and, depending on the product wrapper, may also include protocol incentives; Venus documentation states that supply APY is earned from lending yield and net APY is supply APY minus borrow APY in the trade context.

However, that documentation does not prove the pool’s current primary yield source or a 30d negative outcome.

Evidence (4)

Governance & Legal

governance

two sources

Assessment — Venus Core Pool, BNB Chain; checked September 13, 2026. Governance is real but hybrid, not purely symbolic. XVS holders lock/delegate voting power through XVSVault, submit/vote on Venus Improvement Proposals (VIPs), and successful proposals execute through Governor Bravo and timelocks. Normal VIPs document a 48-hour delay; Fast-track and Critical paths document 6-hour and 1-hour delays respectively. Control surface. The documented BSC contracts are Governor Bravo 0x2d56…c75a, ACM 0x4788…355, Normal Timelock 0x939b…6396, FastTrack Timelock 0x555b…ce02, Critical Timelock 0x213c…f606d, plus three guardians.

ACM permissions allow selected operations outside ordinary DAO execution: risk-parameter changes, oracle actions, and fine-grained pause/resume; Venus explicitly states some actions may be executed directly by guardian multisigs. This is a material centralization/emergency-bypass risk. Proposal-process contradiction. Documentation historically states a 300,000-XVS proposal threshold, while the governance repository’s June 29, 2026 changelog records intended changes to a 1,000,000-XVS threshold and 1,500,000-XVS quorum. Effective deployed values are Not verifiable as of September 13, 2026 because Dune/on-chain calls are unavailable. Voting concentration/top holders. Not verifiable as of September 13, 2026.

No Dune query or execution ID is available in this run. Multisig. Guardian addresses are disclosed, but signer identities, owner counts, threshold, independence, and whether the ACM/guardian wallets are Safe contracts are Not verifiable as of September 13, 2026. No reliable company/legal entity, jurisdiction, registration number, directors, or protocol-specific ToS were identified; do not attribute unrelated “Venus” Terms pages to this protocol. Contradiction / risk callout: DAO voting controls normal governance, but ACM-granted guardian permissions permit unilateral operational intervention without a full token-holder vote. Funds are not shown by available evidence to be directly drainable by an admin; definitive verification is unavailable.

Timelock
Yes
Timelock delay hours
48
Emergency bypass
Yes
Dao governance
Yes
Evidence (5)

legal & regulatory

two sources

Venus Core Pool is part of the Venus Protocol, a lending/borrowing protocol originally launched on BNB Smart Chain (BSC). It operates as a decentralized smart-contract protocol; there is no clear, universally recognized corporate entity owning all deployed contracts, and on-chain verification is not possible in this run ("Not verifiable as of 2026-09-04"). Entity / Jurisdiction Open web sources and documentation typically refer simply to “Venus Protocol” without tying it to a clearly disclosed legal entity (e.g. a foundation or company) with verified registration data. Given the lack of reliable, independent disclosures, entity and jurisdiction are Not verifiable as of 2026-09-04. Terms of Service / User Restrictions Public-facing interfaces to Venus (including core pool UIs) generally present as DeFi dApps without prominently published, independent ToS limiting access by jurisdiction, age, or investor type in a way that can be reliably tied to the specific Core Pool instance.

Any ToS text found via Venus’ own site or app counts as unverified marketing claim under this methodology. KYC / AML Venus Core Pool on BSC is permissionless at the smart-contract level: users interact from any wallet; there is no evidence of protocol-level KYC for borrowers or lenders. Some centralized front-ends or third-party gateways might implement KYC, but this would be at the access layer, not at the protocol itself. These arrangements are Not verifiable as of 2026-09-04. Regulatory Classification / Enforcement / Warnings No independent record from major regulators (e.g.

SEC, CFTC, ESMA, UK FCA, MAS) specifically classifying Venus Core Pool or taking enforcement action against Venus Protocol as such was found. Therefore:

  • active_enforcement: null (no confirmed direct regulator action against Venus Core Pool / Venus entity).
  • No official regulatory warnings specifically targeting Venus were identified; broader DeFi/stablecoin/lending guidance may still apply by analogy. Sanctions There is no indication that Venus Protocol or Venus Core Pool itself is listed on OFAC, EU, UN, or UK sanctions lists.
  • sanctioned: null (not found on major sanctions lists; not independently verifiable on-chain as of 2026-09-04). Data Protection / Actual Legal Risk As a non-custodial, smart-contract based protocol, users transact via public blockchain addresses; standard web privacy rules (cookies, analytics, tracking) depend on the front-end operator and are Not verifiable as of 2026-09-04. Actual legal risk for institutional users stems from:
  • Possible characterization of activities as unlicensed lending, collective investment, or derivatives in some jurisdictions.
  • Counterparty/consumer protection concerns since there is no clear regulated entity, no deposit insurance, and limited recourse.
  • Exposure to broader DeFi regulatory actions that could later reference Venus-like lending protocols even absent current enforcement. Contradiction box: No direct contradictions identified between independent analytics and protocol marketing on legal/regulatory status; the main gap is lack of independently verifiable legal entity and jurisdiction (a finding in itself).
Evidence (5)

legal registries

two sources

No exact GLEIF LEI record for 'Venus Core Pool'. OFAC SDN screening of 'Venus Core Pool': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Venus Core Pool
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Venus Core Pool issues its own stablecoin, VAI, a synthetic USD-pegged stablecoin on Venus. A depeg has been explicitly discussed in Venus materials and third-party coverage, but the exact depeg count, last depeg date, and maximum depeg percentage are not verifiable from the gathered web sources alone, so those fields remain unknown; stable is therefore set to false because the protocol’s own stablecoin has had depeg risk/history.

Own stablecoin
Yes
Stable
No
Stablecoin ids
  • VAI
Evidence (4)

Risks & Strengths

risks

unverified

Venus Core Pool’s principal risks are oracle integrity, liquidation/insolvency during market stress, smart-contract defects, privileged governance actions, and collateral depegs. A material warning occurred on August 15, 2026, when the lisUSD oracle briefly diverged from the DEX price and borrowing was paused; this supports treating oracle risk as demonstrated rather than theoretical. On-chain exposure concentration and current reserve coverage: Not verifiable as of September 5, 2026.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Oracle failure or manipulationIncorrect prices can permit undercollateralized borrowing, bad liquidations, or market freezes. The lisUSD incident demonstrates operational oracle-failure risk.HighMediumResilientOracle uses main, pivot, and fallback sources; DeviationSentinel compares oracle and DEX prices and can pause borrowing or supply.Source outages, stale feeds, configuration errors, and trusted-keeper compromise remain possible.
Liquidation shortfall and bad debtSharp collateral declines, thin liquidity, or congested execution can leave debt insufficiently collateralized and socialize losses across the Core Pool.HighMediumCollateral factors, liquidation thresholds, close factors, liquidation incentives, supply/borrow caps, and forced-liquidation controls are available.Protection depends on timely prices, liquidators, market depth, and correctly calibrated parameters.
Smart-contract implementation defectsA flaw in VTokens, Comptroller/Diamond facets, oracle routing, or liquidation logic could enable asset theft, accounting errors, or an incorrect pause.HighMediumMultiple audits and targeted reviews cover Core Pool, Comptroller, oracle, liquidation, and income-allocation changes; guardians can pause functions.Audits are point-in-time assessments and do not eliminate undiscovered vulnerabilities or upgrade risk.
Governance and privileged-access failureCompromised keys, malicious voting, or erroneous parameter changes could alter markets, oracles, caps, or pause controls.HighMediumRole-based Access Control, normal/fast-track/critical timelocks, proposal cancellation, and separate guardians constrain sensitive actions.Emergency routes and privileged roles retain trust assumptions; key compromise can bypass normal governance delays.
Collateral depeg and contagionStablecoin or wrapped-asset depegs can make collateral valuations unreliable, trigger cascaded liquidations, and transmit losses between correlated Core Pool markets.HighMediumOracle validation, collateral-factor controls, deviation-triggered pauses, market caps, and market deprecation are available.Issuer, reserve, freeze, bridge, and liquidity risks remain external to Venus and may emerge faster than governance can respond.
Evidence (5)

strengths

unverified

Venus Core Pool’s main strengths on BNB Chain are: deep liquidity and long operating history as the protocol’s primary pool; efficient yields/borrowing economics from BNB Chain’s low fees and fast finality; strong security posture with multiple audits, continuous bug bounties, monitoring, and risk-fund support; robust oracle and risk controls using multiple price feeds plus governance pause/risk mechanisms; and broad composability because assets follow standard BEP-20/ERC-20 interfaces and integrate easily with other DeFi tools. The protocol also states that it has the deepest liquidity on BNB Chain and that the Core Pool receives deposits first, which supports its role as the system’s most established market.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 19 two independent sources, 18 one source, 12 unverified.
  • Oldest fact verification date: 2026-08-29.