Decentralized finance protocol Volo disclosed a security breach that drained about $3.5 million from a small number of its vaults. The team said the stolen assets included Wrapped Bitcoin (WBTC), Matrixdock Gold (XAUm) and USDC. Volo detected the incident, alerted the Sui Foundation and ecosystem partners, froze the affected vaults and took steps to limit further exposure.
Volo says the exploit was limited to three isolated vaults and did not indicate a systemic vulnerability across the platform. Roughly $28 million in total value locked across Volo’s other vaults remains secure. The protocol has stated it intends to absorb the losses rather than pass them to users, though specific remediation steps have not yet been finalized.
Volo operates as a liquid staking platform on the Sui blockchain: users stake SUI and receive voloSUI (VSUI) in return. The incident follows a turbulent weekend in DeFi, during which liquid restaking protocol Kelp suffered a far larger exploit of about $293 million, increasing scrutiny across the ecosystem.
In subsequent updates, Volo reported it has frozen or blocked about $2 million of the stolen funds to date. An initial statement said roughly $500,000 was frozen; a later update said the team successfully blocked an attacker attempt to bridge 19.6 WBTC, removing those coins from the adversary’s control. Volo is coordinating with partners to determine the best options for recovering and returning funds.
The attack is the latest in a long history of crypto security incidents. Over the past decade, more than $17 billion has been stolen from crypto projects, with private-key compromises often cited as a major cause. Data compiled by DeFiLlama indicate that roughly 22.3% of incidents involve brute-force key compromises, 18.2% are attributed to unknown methods, and about 10% result from phishing attacks targeting multi-signature wallets—underscoring that many large losses stem from wallet and user-side security issues rather than direct protocol flaws.
Readers are encouraged to verify details independently; the reporting here follows the original coverage and related public statements by Volo.