Volo Protocol, a BTCFi and liquid staking hub on the Sui Network, has confirmed a security incident that resulted in the loss of approximately $3.5 million in digital assets from three of its vaults. The affected funds included WBTC, XAUm, and USDC.
In an official statement, the Volo team confirmed that the incident was detected promptly, following which the team alerted the Sui Foundation and other ecosystem partners to contain the damage, and immediately froze the affected vaults to prevent further losses.
The team also stated it is prepared to absorb the losses and aims to avoid passing the financial impact onto users: “We want to be clear: Volo is prepared to absorb this loss.” The protocol also shared a follow up update to the statement, reporting that the team successfully blocked the hacker from bridging out 19.6 WBTC after the $3.5M exploit on three Sui vaults, keeping those funds fully under control. They’ve already frozen ~$500K in related assets with ecosystem partners, plan to return the intercepted WBTC, and will absorb all losses themselves.
Investigation underway
According to the official update, the attack targeted only three specific Volo Vaults. All vaults have now been frozen pending a comprehensive post-mortem and remediation process.
“We are actively working with on-chain investigators and ecosystem partners on further recovery,” the team said, adding that a detailed post-mortem will be released after the investigation concludes.
Despite the breach, Volo clarified that approximately $28 million in total value locked (TVL) across other vaults remains secure. The protocol emphasised that the attack vector was isolated and did not impact the broader system.
Broader security concerns
The incident comes amidst a period of heightened cyber risks. A recent breach involving Vercel has raised concerns about supply chain vulnerabilities and compromised third-party integrations, particularly involving AI tools.
The Volo exploit adds to a growing list of attacks targeting decentralized finance platforms, highlighting persistent vulnerabilities in smart contract ecosystems. While rapid response measures helped limit further damage, the case underscores the importance of continuous monitoring, robust security audits, and stronger safeguards across both on-chain and off-chain infrastructure.
Also read: Ice Open Network Breach Exposes User Data in Third-Party Hack
