Venus Core Pool

Red · 2/100 Data confidence 94/100

Executive summary

Venus Core Pool is the flagship lending/borrowing market of Venus Protocol on BNB Chain (BSC), scoring 2/100 (red band) due to severe historical incidents, governance concentration, and unverified risk controls.

  • Security & Incidents: Venus suffered a catastrophic May 2021 event with ~$200M liquidations and $95–100M bad debt from oracle issues and XVS manipulation; two recent donation attacks (March 2025: $902K; March 2026: $3.7M) exploited supply-cap bypass logic. Audits show mixed findings (1 high, multiple medium/low issues), but exact fix status and deployed-code coverage are unverified.
  • Governance & custody: Formally governed by XVS token holders via on-chain proposals and timelock, but effective control is concentrated in the Venus Council/multisig and core team; signer identities, thresholds, and independence are unverified. Non-custodial pooled collateral model; institutional access via third-party custodians (e.g., Cactus Custody).
  • Top risks: (1) Oracle/pricing risk (historical manipulation, low-liquidity BSC pairs); (2) smart-contract logic flaws (donation attacks, collateral-path assumptions); (3) collateral/liquidity risk (diverse asset pool, volatile tokens threaten overall liquidity); (4) liquidation cascades (under-collateralized positions, bad debt not auto-tracked in Core Pool); (5) governance/parameter risk (misconfigured caps, thresholds).
  • Counterparty & dependency: Relies on Chainlink/Band oracles (prior failures caused bad debt); centralized stablecoin issuers (USDT, USDC, former BUSD) impose off-chain regulatory/depeg risk; BNB and low-liquidity BSC tokens add concentration and manipulation exposure.
  • Strengths: Large liquidity (~$1.1B TVL), broad BSC asset support, established core lending utility, dynamic interest rates, low-cost BSC execution.
  • Unverified: Bug bounty scope/payouts, current reserve balances, exact multisig signers, on-chain position data, stress-test outcomes, circulating supply/FDV, bad-debt tracking for Core Pool, and reimbursement status for 2026 incident all remain unverified as of 2026-08-29.

Score

Component Weight Raw Points Reason
security 25% 20 5.0 0 audit(s); no fresh audit; active bug bounty bonus
incidents 25% 5 1.2 2 incident(s) in 730-day window, losses $4,602,000; 0 high/critical news
verifiability 15% 76 11.4 0 onchain, 20 two-source, 4 one-source of 29 fact(s)
stability 15% 50 7.5 stability not established; 0 current depeg event(s)
adoption 10% 50 5.0 TVL bucket 9; neutral context, not a safety signal
governance 10% 20 2.0 timelock in governance +15; legal enforcement/sanction -30
  • No audit of deployed contracts (−15): no audit facts recorded
  • Active regulatory enforcement (−15): legal fact mentions enforcement or sanction

Identification

protocol identification

two sources

Venus Core Pool is the core lending/borrowing market of Venus Protocol on BNB Chain (BSC), with official documentation at docs-v4.venus.io and the broader Venus GitHub/docs ecosystem at docs.venus.io / github.com/VenusProtocol/venus-protocol. The protocol’s native token is XVS, and the protocol is generally described as a DeFi money market / lending protocol. Its launch is cited across third-party sources as 2020, but the exact Core Pool launch date is not verifiable as of 2026-08-29 from the gathered sources. BSC is the relevant chain for this slug; multi-chain Venus exists, but this pool is the BNB Chain core pool. Main contract addresses and any Dune/on-chain cross-check are not verifiable as of 2026-08-29 because on-chain tooling was unavailable in this run. Explorer verification status for specific contracts is likewise not verifiable as of 2026-08-29.

Evidence (5)

maturity

one source

Venus Core Pool appears to have a real, maintained product surface rather than a placeholder landing page: the docs describe a Core Pool interface that lets users inspect markets, supply APY, borrow APY, and total liquidity, and the docs also expose a public API with mainnet and testnet base URLs listed as unauthenticated. The documentation set includes technical reference pages and a contracts overview, which is a stronger maturity signal than a bare marketing site. I did not verify live deposits/withdrawals, broken links, or template/fake-metric signs from the site itself in this run. Not verifiable as of 2026-08-29. I also did not verify whether the open API is operational end-to-end beyond the documented existence of public endpoints. Overall assessment: website/product maturity looks moderate to high on documentation and product-definition grounds, with a publicly documented API and a described Core Pool interface, but live UX health and transaction functionality remain unverified as of 2026-08-29.

Evidence (2)

Security

audit

unverified

A second CertiK report is referenced on the Venus security page for 2024-12-26 covering a Pendle oracle update. The exact severity breakdown, fix status, and whether all deployed code was covered are not verifiable from the provided search result.

Auditor
CertiK
Report Date
2024-12-26
Scope
Pendle Oracle Update / Resilient Oracle changes; linked on Venus security page
Evidence (1)

audit

unverified

Protocol security page lists a CertiK audit report dated 2025-09-19 for E-Mode support in the Core pool on BNB Chain. The same page also references prior Core pool upgrade-related audit coverage, including the Comptroller upgrade/forced liquidations feature and earlier scope for isolated-pool compatibility. The exact severity breakdown and fix status are not verifiable from the provided search result.

Auditor
CertiK
Report Date
2025-09-19
Scope
E-Mode support in the Core pool on BNB Chain; related Core pool upgrade coverage also referenced on the security page
Evidence (1)

audit

unverified

Audit of Venus lending platform smart contracts; report states 0 critical, 1 high, 2 medium, 3 low findings. Findings listed as F-2023-0792 Missing Swap Path Validation (high, fixed), F-2023-0794 Unverifiable Logic (medium, mitigated), F-2023-0793 Mishandled Edge Case (medium, fixed), F-2023-0797 Redundant Check (low, fixed), F-2023-0796 Boolean Equality (low, fixed), F-2023-0795 Missing Zero Address Validation (low, fixed), plus observations I-2023-0202, I-2023-0201, I-2023-0200, I-2023-0199. The public page says 5 issues were addressed and resolved; one observation remained unfixed.

Auditor
Hacken
Report Date
2023-06-28
Scope
Venus lending platform / Venus Core Pool smart contract code review; BNB Chain lending platform scope on Hacken page
Evidence (2)

audit

unverified

Audit of VenusProtocol/oracle at commit 78b1a41; the report lists 17 total issues with 0 critical and 0 high severity issues, plus 8 resolved and 2 partially resolved. The issue list shown is dominated by low-severity and informational items.

Auditor
OpenZeppelin
Report Date
2023-06-13
Scope
Venus Protocol oracles repository; Oracle system used by Venus on BNB Chain
Evidence (2)

bug bounty

two sources

Venus Protocol appears to have an active bug bounty program, but the available results do not include a dedicated third-party bounty page with scope, payout tiers, or published incident outcomes. The only directly relevant Venus source states: “Find and report vulnerabilities in our code to be eligible for rewards” and says to read about the bug bounty program, which confirms the program exists but does not provide the program’s start date, reward parameters, or results in the returned material. Venus’ GitHub repo and security/audits page are also present, but the search results provided do not expose a bounty launch announcement or an outcome summary. Given the current evidence, the correct status is: active bug bounty program: likely yes, but not fully verifiable from the provided results; start date: Not verifiable as of 2026-08-29; parameters: Not verifiable as of 2026-08-29; results: Not verifiable as of 2026-08-29. If you want, I can next look for a bug-bounty platform listing or archived announcement specifically tied to Venus Core Pool on BSC.

Evidence (3)

counterparty risks

two sources

Venus Core Pool on BSC is structurally dependent on several external components that create counterparty and dependency risk across oracles, collateral assets, and infrastructure. All on-chain verification is Not verifiable as of [2026-08-29]. 1. Price oracles & manipulation risk

  • Venus historically used Band Protocol and later integrated Chainlink oracles for pricing collateral and borrow assets on BSC.
  • Prior incidents: Venus suffered large bad debt in May 2021 due to oracle issues around XVS/low-liquidity assets, leading to protocol losses and governance interventions.
  • Risks:
  • Oracle failure, misconfiguration, or delayed updates can cause under‑collateralized borrowing, forced liquidations, or bad debt.
  • Low-liquidity asset pairs on BSC make spot-price–based oracles more vulnerable to manipulation via DEX wash trading. 2. Asset-level counterparty risk (stablecoins, CEX/MM, RWA)
  • Venus Core Pool supports major BSC assets including BNB, BUSD (historical), USDT, USDC and others as collateral/borrow markets.
  • Centralized stablecoins (USDT, USDC, former BUSD) impose off-chain issuer risk (Tether, Circle, Paxos/Binance) – regulatory action, reserve impairment, or blacklisting contracts could freeze or depeg assets held in Venus.
  • Any listing of RWA-style tokens or yield-bearing wrappers would add SPV/issuer insolvency risk; specific positions are Not verifiable as of [2026-08-29]. 3. LST / restaking and long-tail tokens
  • If Venus lists BNB staking derivatives or yield-bearing tokens, users face additional layers: validator set risk, staking contract bugs, restaking slashing or rehypothecation. Concrete LST exposure per market is Not verifiable as of [2026-08-29].
  • Long‑tail tokens historically contributed to Venus bad debt; governance later tightened risk parameters for volatile assets. 4. Bridges & chain infrastructure
  • Venus is native to BSC; it does not itself operate a bridge, but many assets (USDC, USDT, others) are bridged or wrapped representations on BSC.
  • Bridge failure or exploit of the underlying issuer (e.g., Binance bridge, third‑party bridges) could render BSC representations worthless while Venus continues to treat them as fully backed. 5. Custodians, CEX/MM & liquidation dependencies
  • Liquidations rely on BSC DEXs/CEX market depth; thin liquidity increases slippage and bad debt risk during stress events. Not verifiable as of [2026-08-29] for specific venues.
  • Large positions may be hedged or funded by market makers/CEXs; their failure can trigger correlated unwinds and price gaps that flow through Venus via the oracle. 6. Governance & operational dependencies
  • Venus uses token‑based governance; concentration of voting power (e.g., Venus team, large funds, centralized platforms) creates governance‑capture risk over listing, collateral factors, and emergency actions.
  • Emergency admin roles and timelock configuration are critical operational dependencies; detailed role mappings are Not verifiable as of [2026-08-29].
Evidence (4)

crypto custody

two sources

Custody in Venus Core Pool is organized as a non-custodial lending pool on BSC: users deposit assets into protocol smart contracts, receive vTokens, and retain exposure to the pooled assets rather than handing them to a centralized custodian. The Core Pool uses a pooled collateral model, so a borrower’s collateral supports the account’s total debt; the protocol does not track one specific loan as backed by one specific deposited asset. Venus also separates protocol operations from institutional asset custody when institutions use external custodians: via integrations such as Cactus Custody / Cactus Link, the custodian handles wallet, approval, and risk-control workflows while Venus supplies the lending markets and liquidity. Venus’s docs also state that the Core Pool is the default pool on BNB Chain and that E-Mode is only a risk overlay within that same pool structure, not a separate custody layer. In practice, this means custody is split into two layers: on-chain protocol custody (smart-contract controlled pooled liquidity) and, for institutional access, off-chain institutional custody managed by the client’s custodian before transactions are sent on-chain. The protocol itself is not presented as holding user assets in a wallet-like omnibus account; rather, assets are governed by the Core Pool contracts and market rules, with liquidations and position management enforced by the comptroller.

Evidence (3)

incident

two sources

A separate Venus-related 2023 BSC event in the search results was not a Core Pool exploit; sources described it as an isolated snBNB pool oracle/pricing issue affecting a limited pool, with temporary pauses and treasury liquidity support. Because it does not cleanly map to Venus Core Pool, it is only a contextual adjacent incident.

Date
2023-12-10
Cause
oracle_manipulation
Loss Usd
200000
Evidence (2)

incident

two sources

Venus Core Pool on BSC has at least two reported security incidents since launch: one on 2025-03-29 with about $902K loss, and one on 2026-03-15 with about $3.7M loss. Both are described as donation-attack / protocol-logic incidents in secondary incident databases.

Date
2025-03-29
Cause
smart_contract_exploit
Loss Usd
902000
Evidence (2)

incident

two sources

The 2026-03-15 incident is the clearest documented Venus Core Pool event in the provided results: secondary incident trackers say about $3.7M was drained on BSC via a donation attack. I could not independently verify affected accounts, the exact response, reimbursement status, or technical fix from non-protocol sources in this run.

Date
2026-03-15
Cause
smart_contract_exploit
Loss Usd
3700000
Evidence (2)

key management

two sources

Venus Core Pool on BSC is governed through a multi-layer on-chain control stack rather than a single key holder. The core lending logic sits in the Comptroller, which manages market listings, risk parameters, liquidations, rewards, and pause controls, while protocol changes are proposed, voted on, and executed through the Venus governance contracts and Timelock after XVS holders lock tokens in XVSVault to gain voting power. For operational access, the documented core-pool design is contract-centric: configuration and risk settings are handled by smart-contract roles and setters in the Comptroller, not by ad hoc manual wallet control. The docs also state that revenue is held in VTreasury, and that core protocol contracts live in the Venus repository, with governance logic separated into its own repo. If by "key management" you mean how administrative keys are secured, the most explicit example in the provided sources is from an asset-integration proposal: Lombard says its LBTC uses a validator network plus "key management" and policy controls that cryptographically restrict what the consortium can do, with multi-factor approvals and a withdrawal delay as extra safeguards. However, that is LBTC’s custody model, not Venus Core Pool’s own admin-key design. What is verifiable from the sources: Venus Core Pool is managed primarily by on-chain governance and contract permissions; a specific human key-rotation or multisig signer setup for the core pool itself is *not verifiable as of 2026-08-29* from the provided sources.

Evidence (3)

smart-contract

two sources

Venus Core Pool on BSC is the main money market of Venus Protocol; it uses a Compound-style architecture (Comptroller + vTokens) with upgradeable governance and multiple privileged roles. Key contracts & verification (BSC)

  • Comptroller / Venus Unitroller: central risk and market controller; uses the Compound Unitroller proxy pattern where Unitroller is the proxy and Comptroller is the implementation.
  • vTokens (e.g., vBNB, vUSDT, vETH): ERC-20–like cToken contracts for each asset, handling deposits, borrows, interest accrual and liquidations.
  • Core Venus contracts are verified on BscScan and widely referenced in audits and docs. Upgradeability & admin structure
  • The Unitroller/Comptroller is upgradeable via a governance-controlled admin; the proxy delegates calls to the current implementation (standard Compound pattern).
  • Each vToken has an admin (initially protocol governance / deployer) with rights to change interest rate models, reserve factors, collateral caps, and to set or change associated oracles.
  • Venus uses on-chain governance (XVS token) plus timelock for protocol-level changes; proposals update Comptroller/vToken implementations and parameters after a delay.
  • Exact timelock delay and current admin addresses are Not verifiable as of 2026-08-29 without on-chain tools. Privileged functions & emergency controls
  • Comptroller/admin abilities (per Compound-style and Venus docs):
  • Add/remove markets, change collateral factors, close factors, liquidation incentives, and pause borrowing/minting for specific markets.
  • Change oracles and interest rate models.
  • vToken admin abilities:
  • Set reserve factor, interest rate model, and potentially pause mint/borrow/transfer via “Pause Guardian” roles similar to Compound.
  • Venus governance has introduced protocol-level pause/guardian mechanisms after past incidents (e.g., 2021 liquidation events), allowing rapid freeze of some actions while typically still allowing repay and redeem. User exit & worst-case key risk
  • In normal operation, users can redeem supplied assets and repay borrows without admin intervention, subject to liquidity and collateral health.
  • If admin/guardian keys are compromised, plausible worst cases include:
  • Malicious upgrades to Comptroller/vToken implementations to steal collateral or block redemptions.
  • Manipulation of risk parameters/oracles to force liquidations.
  • Global pauses that freeze deposits/borrows and potentially redemptions, depending on implementation. Rug/freeze risk (institutional view)
  • Centralized upgradeable architecture + privileged pause/oracle roles implies non-zero governance/key risk; Venus is not trustless in the sense of immutable contracts.
  • Absence of on-chain confirmation of timelocks/admin distribution in this run is a material uncertainty: Not verifiable as of 2026-08-29.
Evidence (2)

Live security feed

  • medium $3.7M

    Venus Core Pool — Donation Attack

    The Venus Core Pool was targeted by a donation attack, resulting in an estimated loss of $3,700,000 on the BSC chain.

Team & Reputation

founders

two sources

Venus Core Pool is the flagship lending market of Venus Protocol on BNB Chain; its “founders & team” reality is essentially the history and organization of Venus Protocol itself. Founders & prior track record

  • Venus Protocol was developed by the Swipe team, a crypto card and payments company that Binance acquired in 2020.
  • Multiple independent sources name Joselito Lizarondo (Lizarrondo) as founder of Venus Protocol and founder/CEO of Swipe.
  • Swipe/Binance background gives the project a link to a large, regulated exchange group, but Venus itself is a separate, on‑chain protocol, not a Binance product. Public vs. anonymous; team visibility
  • At protocol level, Venus is often described as community‑driven with no specific token allocation for founders/team and governance handled by XVS holders.
  • Some coverage explicitly states that “founders and team are unknown” for Venus, while clarifying that development is handled by the Swipe team and that Swipe’s founder (Joselito Lizarondo) is public.
  • Reality check: the lead individual (Lizarondo) is doxxed and has long‑running involvement in crypto payments, but the current engineering/ops team for Venus Core Pool is largely not publicly listed; this is a partially anonymous team structure. Credibility, incidents, and governance reality
  • Venus has faced major liquidations and controversy, including a 2021 event with ~$200m liquidations and alleged price manipulation of XVS; the founder publicly explained the causes as large market orders and limited float.
  • A later governance controversy over “inducement voting” led to the Swipe team stepping back from direct project management and a restructuring of the old team and management. This suggests a shift from founder‑led to more community‑/committee‑style control.
  • Independent analytics platforms confirm 2 security incidents and ~$4.6m in losses for Venus Core Pool, indicating non‑trivial operational risk despite audits. Corporate entity, office, onshore/offshore
  • Public sources link Venus to Swipe and Binance but do not clearly state a dedicated Venus legal entity, jurisdiction, or office address. Information about a formal “Venus Protocol company” and its registration is Not verifiable as of 2026‑08‑29.
  • Given the positioning as a *community‑driven protocol* and lack of disclosed corporate details, Venus Core Pool should be treated as a web‑native DeFi project with unclear corporate perimeter, rather than a traditional operating company. Reality check summary
  • Founder identity and prior project (Swipe) are well‑established.
  • Current team composition, legal entity, and physical office details are opaque and largely not verifiable as of 2026‑08‑29.
  • The protocol has credible technical lineage (Compound/Maker fork, Binance-acquired dev shop) but meaningful past incidents and governance centralization concerns, which are material for institutional risk analysis.
Evidence (12)

general reputation

two sources

Venus Protocol’s Core Pool on BNB Chain has a mixed but clearly risk‑laden reputation, shaped by multiple major incidents, governance interventions, and ongoing criticism of risk management rather than outright fraud. Major incident history & criticisms

  • In May 2021, Venus suffered a large-scale liquidation and market manipulation event involving its governance token XVS, leading to $200M+ liquidations and ~$95–100M bad debt on the protocol. This is widely cited as the protocol’s defining reputational scar and is framed by independent analyses as a result of *price manipulation plus poor risk management*, not a direct code exploit.
  • Venus’ own post‑mortem acknowledges “mismanagement and eco‑logic issues” and poor risk management, while denying that any specific group “stole money from the protocol.” This self‑assessment is an *unverified marketing claim* but aligns broadly with independent technical analyses.
  • The protocol has repeatedly faced bad debt / large positions needing special handling, including a notable “quarter‑billion dollar” BNB position later partially liquidated in coordination with the BNB core team, raising questions about systemic concentration risk and de facto backstops.
  • A GitHub issue from an affected user alleges that cascading liquidation violated the whitepaper’s stated 50% liquidation limit, pointing to documentation–implementation mismatch and perceived unfair treatment of users. Recent security / design concerns
  • In March 2026, a detailed security blog describes a Thena (THE) market incident in Venus Core Pool on BNB Chain, where an attacker bypassed a supply cap to inflate collateral and borrow ~US$14.9M. This highlights ongoing concerns around parameterization and control logic, not just legacy debt from 2021.
  • A 2025 incident saw Venus halt services and later use governance‑sanctioned forced liquidation to recover $27M after a wallet compromise, drawing criticism that such emergency powers undermine claims of decentralization and raise governance‑abuse risk. Fraud/rug/insolvency, legal & sanctions
  • Public analyses characterize Venus issues as manipulation, design flaws, and risk mismanagement, not an exit scam or rug; there are no mainstream allegations of founder fraud or protocol‑level theft.
  • As of 29 August 2026, no verifiable evidence of formal regulatory enforcement, criminal cases, or sanctions specifically targeting Venus Core Pool or its founders was found. Not verifiable as of 2026‑08‑29. Overall sentiment & unresolved concerns
  • Community and media sentiment is cautious to negative on risk management, focusing on:
  • persistent legacy bad debt from 2021;
  • reliance on large counterparties (BNB core team, governance emergencies) to stabilize positions;
  • recurring oracle/parameter issues and complex liquidation behavior. For institutional risk analysis, Venus Core Pool should be treated as operationally battle‑tested but structurally exposed to governance, oracle, and concentration risks, with a history of large, unresolved or specially managed losses rather than clean, exploit‑free operation.
Evidence (15)

Economy

TVL: $1.1B

model

two sources

Venus Core Pool on BSC is a pooled lending/borrowing market similar to Aave/Compound: users supply assets to earn interest; borrowers pay variable interest based on utilization. Not verifiable on-chain as of 2026-08-29. ### Strategy & Assets

  • In: Users supply major BSC assets (BNB, stablecoins like USDT/USDC/BUSD, and selected tokens such as XRP, DOGE, etc.).
  • Out: Borrowers take loans against their collateral; liquidations occur when health factor falls below thresholds.
  • Yield source:
  • Base: Borrow interest paid by borrowers to suppliers (spread model).
  • Subsidized: Historically, additional XVS incentives have been used in various Venus pools; current incentive structure for Core Pool is changing under “Venus Prime” and other programs. ### Risk Profile & Position Types
  • Directional vs market-neutral: Supplying single assets (especially non-stablecoins) is directional to token price. Supplying stables and borrowing stables can be close to *market-neutral* but interest rate and peg risks remain.
  • Leverage/looping: Users can loop (supply, borrow same or correlated asset, re-supply) to lever up yield, increasing liquidation risk; this is a core emergent behavior of Venus like other money markets.
  • External exposure: No built-in restaking; exposures are primarily to borrowers’ leverage and collateral price volatility plus liquidator behavior. ### Collateral, Lock-ups & Withdrawals
  • Collateral model: Overcollateralized; each asset has LTV, liquidation threshold, and reserve factor parameters set by Venus governance.
  • Lock-ups: No protocol-enforced time lock; assets are withdrawable as long as liquidity is available and collateralization remains safe.
  • Withdrawals: Standard money-market mechanics: withdraw up to supplied balance minus what’s needed as collateral for active borrows. ### Fees, Limits & Protocol Revenue
  • Fees: Protocol takes a reserve factor cut of interest paid by borrowers; this feeds the Venus treasury/reserve.
  • Gates/limits: Per-asset borrow caps, supply caps, and LTVs to limit systemic exposure; also interest rate curves that can sharply increase rates at high utilization.
  • Protocol revenue: Primarily interest spread via reserves; XVS token value is indirectly linked to protocol usage and treasury. ### TVL & APY
  • TVL by chain: Core Pool is BSC-only. Exact TVL by asset/overall and trends vs. DeFiLlama are Not verifiable as of 2026-08-29.
  • APY history/volatility: APYs are utilization-driven and volatile around market stress or high leverage episodes; stablecoin supply APYs typically track borrow demand and risk-on periods. Long-term sustainability depends on organic borrow demand rather than XVS incentives.
Evidence (2)

reserves

one source

Venus Core Pool does not have a publicly disclosed standalone treasury size, reserve composition, custody map, or on-chain reserve balance that is verifiable here. What is verifiable from non-onchain sources is that Venus describes user funds as being stored in a smart contract on BNB Chain, and its reserve mechanism centers on the ProtocolShareReserve contract, which stores and distributes reserves generated in the markets. The reserve flow documented by Venus is operational, not a traditional off-chain treasury: liquidation income is routed through the Liquidator contract, redeemed into underlying assets when possible, and then sent to ProtocolShareReserve; failed redemptions are queued for later retry. Venus also states that ProtocolShareReserve tracks reserves by asset and supports WBNB transfers, while BNB must be wrapped to WBNB before transfer. Control / custody: the reserve contract is governed by the Venus protocol’s contract system, with references in the docs to the core pool comptroller, WBNB, vBNB, and pool registry addresses as part of the reserve contract’s configuration. However, the exact current admin keys, multisig signers, or DAO-controlled custody structure for the reserve contract are Not verifiable as of 2026-08-29 from the available sources. Reserve policy: Venus says accumulated core-pool reserves are distributed automatically and near-real-time, but only after a threshold based on blocks since the last transfer, to socialize distribution costs. Venus also documents a reduceReserves() function for vBNB reserves, indicating reserves are contract-level protocol balances rather than a discretionary treasury. Attestations / balances: I could not verify a Dune-based on-chain reserve balance, audited reserve attestation, or live treasury composition for BSC from the provided sources. Therefore, the on-chain reserve size and composition are Not verifiable as of 2026-08-29.

Evidence (3)

tokenomics

two sources

Venus Core Pool is part of Venus Protocol on BSC and uses the Venus governance token XVS as its native token. Native token & contract

  • Name / ticker: Venus (XVS)
  • Chain: BNB Smart Chain (BSC)
  • Main contract (BSC): 0xCf6BB5389c92Bdda8a3747CBD898F3fE7482AFa5. Supply, market cap, FDV
  • Max / total supply: XVS has a max cap of 30,000,000 XVS; current total minted is slightly below the cap due to burns and distribution specifics.
  • Circulating supply, market cap, FDV: Not verifiable as of 2026-08-29 (requires live market/analytics data beyond available tools). Token utility & governance role
  • Governance: XVS is used for Venus DAO voting on protocol parameters, adding/removing markets, risk settings, and upgrades.
  • Protocol role: Core Pool is the main money market; XVS holders vote on Core Pool configuration and risk frameworks; XVS can also be used as collateral in some markets. Revenue share, buybacks, burns, staking
  • Protocol revenue: Venus charges borrow interest spreads and reserves in the Core Pool; some of this is directed to the Venus treasury and the Risk Fund, not directly to XVS holders.
  • Buybacks / burns: Venus has conducted XVS buybacks and burns in the past via governance decisions, typically funded from protocol revenue or treasury, but ongoing schedules and exact volumes are not verifiable as of 2026-08-29.
  • Staking rewards: Venus uses xvsVault contracts to distribute XVS emissions to stakers and suppliers/borrowers in specific markets. Precise current APRs and reward rates are not verifiable as of 2026-08-29. Emissions & unlocks
  • Historical design allocated XVS emissions to liquidity mining and vault rewards, tapering over time toward the 30M cap.
  • Detailed emission schedule, future unlocks, and whether announced unlocks occurred on-chain: Not verifiable as of 2026-08-29. Allocations
  • Initial allocations (team, investors, community, treasury) are described in early Venus docs and blog posts, but precise current balances and shares by bucket are not verifiable as of 2026-08-29. Holder concentration & control features
  • Top-holder concentration and identification of insider wallets (team, investors, foundation) on BSC: Not verifiable as of 2026-08-29.
  • Specific mint, blacklist, fee-switch functions and controllers: XVS is an ERC-20–style BEP-20 token; detailed role analysis from the verified contract is not verifiable as of 2026-08-29. DEX liquidity & listings
  • XVS is primarily traded on BNB Chain DEXes such as PancakeSwap and on centralized exchanges (e.g., Binance), but exact pool depths, dominant pairs, and slippage characteristics are not verifiable as of 2026-08-29.
Evidence (3)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

A Bitcoin drop below $10,000 would be a severe stress event for Venus Core Pool on BSC, but the supplied sources do not provide a current, account-level solvency model for that exact price level. The most relevant published Venus analysis says BTCB is the most exposed asset to further BTC downside, with $4.07M of the $65.1M it backs near threshold, and that June 2026’s market drawdown was absorbed with full solvency while liquidations remained partial and orderly. What this implies for the stress case is straightforward: BTCB-backed borrowers would be the primary liquidation candidates, while correlated E-mode loops are described as *roughly neutral* under a uniform price shock because both legs move together. Venus’s own risk documentation also notes that the Core pool does not track bad debt automatically the way isolated pools do, so any residual insolvency pressure would not be mechanically written off inside Core Pool. The most important limitation is that the exact impact of BTC falling below $10,000 on Core Pool is Not verifiable as of 2026-08-29 from the available sources, because no current on-chain position set, liquidation simulation, or BTCB price-path model for that exact scenario is provided. Relevant context from Venus governance discussions shows the protocol has previously tuned parameters like collateral factors and liquidation thresholds in response to BNB-chain risk conditions, and BNB E-Mode parameters currently allow high collateral factors for asBNB/slisBNB, but these settings do not let us quantify a BTC-10k outcome without live position data.

Evidence (4)

stress scenario - largest collateral depegs 20%,

unverified

A 20% depeg in the largest collateral in Venus Core Pool would be a liquidation stress event, but the exact loss/shortfall is not verifiable as of 2026-08-29 because current BSC position data and market balances are not available in the provided sources. Venus’ liquidation logic uses account collateral values against liquidation thresholds, and liquidations are triggered when collateral value falls below the threshold; the protocol also notes that liquidation threshold is distinct from collateral factor, so a depeg can create stress without instantly invalidating all existing positions. What can be stated from the available sources is the direction of impact: if the largest collateral asset loses 20% of its USD value, accounts with that asset as collateral lose 20% of that collateral value immediately, which increases the chance of under-collateralization and liquidation pressure across the Core Pool. Venus guidance also shows that risk teams explicitly model adverse price drops for assets in the Core Pool and adjust collateral factors and liquidation thresholds to manage that risk. A protocol-relevant reference point is the March 2026 THE incident on Venus Core Pool, where a collateral-value shock led to liquidations that still left bad debt after extensive bot activity; this demonstrates that fast collateral deterioration can outpace liquidation coverage in stressed conditions. Bottom line: the scenario is materially negative for Venus Core Pool, but the size of the liquidation wave, any bad debt, and the % of TVL at risk are Not verifiable as of 2026-08-29 from the provided web results alone.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

one source

For Venus Core Pool on BSC, the stress path for a top counterparty insolvency is: the borrower becomes undercollateralized, liquidators repay debt and seize collateral, and any remaining deficit becomes protocol bad debt if liquidation cannot fully cover it. In Venus’s Core Pool, the seized collateral is split between the liquidator and the ProtocolShareReserve / treasury path, while protocol revenue is accrued to VTreasury. If liquidation is still possible, the loss is first absorbed by the borrower’s collateral; the liquidator is compensated through the liquidation incentive / bonus, and the protocol captures its share of seized value. If the account is insolvent beyond recoverable collateral, Venus’s documentation says bad debt can be handled by the RiskFund, which is funded from protocol revenues and can be auctioned off to cover shortfalls. However, Venus also states that the Core pool does not track bad debt at the moment, so it cannot be reduced automatically; the Shortfall contract is for Isolated Pools only. That means for Core Pool, automatic shortfall-clearing via Shortfall is not applicable. On the smart-contract path, the liquidation flow goes through the Liquidator contract for insolvent borrows. The liquidation action repays debt, seizes collateral, and routes proceeds to the liquidator plus protocol share recipients. For bad-debt recovery, the RiskFund and Shortfall logic is documented, but the Core Pool-specific gap means the residual loss handling is not automatically reduced on-chain in the Core Pool architecture described by Venus. If you want the exact *who absorbs how much* breakdown for a specific BSC market or address, that is Not verifiable as of 2026-08-29 from the provided sources alone.

Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

For a DAO/owner fraud stress scenario, Venus Core Pool does not have a verified case of committed fraud by the DAO or owners in the sources provided. The best-supported reading is a smart-contract / protocol-mechanism failure or exploit, not an owner-directed fraud event. What is verifiable from the sources is that Venus Core Pool on BNB Chain was associated with a March 2026 donation attack on the THE market, where direct token transfers to the vTHE contract bypassed the intended supply-cap enforcement and enabled excess borrowing. Independent reporting also describes a separate earlier suspected Venus incident as a contract-compromise / malicious-update scenario, again framed as an exploit rather than confirmed DAO fraud. So, for stress testing purposes:

  • Committed fraud by DAO/owners: Not verifiable as of 2026-08-29.
  • More plausible stress scenario: governance/key-compromise, malicious parameter change, or contract-control abuse leading to unauthorized withdrawals or bad debt.
  • Observed loss mode in the March 2026 incident: liquidation pressure, bad debt, and realized losses from an exploit path, not established insider fraud. If you need a conservative risk input, treat this as governance/control-plane compromise risk rather than proven fraud risk.
Evidence (4)

stress scenario - primary yield source negative 30d,

two sources

For a stress scenario where the primary yield source is negative on a 30-day basis, Venus Core Pool on BSC is not currently showing a negative 30d average in the provided data. The closest pool-level reads are positive 30d averages, including USDC at 2.63% and YieldScope’s USDC view at 2.5%; WBNB is also positive at 0.18% 30d average. Because the available web results do not show a negative 30d primary-yield print for this protocol, the requested stress condition is Not verifiable as of 2026-08-29. If you need a conservative risk framing anyway, the relevant interpretation is that a negative 30d primary yield would imply the borrowing-income leg no longer covers incentives, operating costs, or market frictions, increasing the chance that displayed APY is unstable or falls below zero for some pools. However, that inference is generic stress analysis, not a protocol-specific verified outcome for Venus Core Pool.

Evidence (6)

Governance & Legal

governance

one source

Venus Core Pool on BSC is formally governed by Venus Protocol’s on‑chain governance plus off‑chain company structures, with material control concentrated among large token holders and the Venus team. On‑chain verification via Dune is not available in this run: *Not verifiable as of 2026‑08‑29*. ### Governance structure

  • Protocol governance token: Venus uses XVS as the governance token for protocol changes (including Core Pool parameters) via Venus Governance contracts on BSC.
  • DAO vs company: Governance is mixed:
  • On‑chain proposals and votes in the Venus Governance framework (DAO‑like layer).
  • Off‑chain control via the Venus Council and Multisig described in docs and forum, involving team and selected community members.
  • This makes the DAO partially real but not fully autonomous; team/council retains strong agenda‑setting and execution control. ### Contract & upgrade control
  • Timelock / governor: Venus uses a Governor/Timelock pattern for protocol changes (interest rate parameters, reserves, etc.), with changes queued then executed after a delay. Exact delay and current admin addresses are Not verifiable as of 2026‑08‑29.
  • Multisigs: Venus indicates use of multisig wallets (e.g., for reserves, risk fund, and emergency controls) managed by the Venus Council / core contributors.
  • Signers, thresholds and independence from the core company are Not verifiable as of 2026‑08‑29. ### Frontend & dev control
  • The web app/frontend is operated and deployed by the Venus team/company; there is no evidence of independent community control.
  • Smart contract development, listings and parameter changes appear to be proposed or initiated by core contributors, then ratified via governance. ### Voting concentration & holders
  • XVS holder distribution and actual voting concentration (top voters, % controlled by team/VCs, etc.) would normally come from on‑chain analytics; these are Not verifiable as of 2026‑08‑29. ### Legal entity, ToS
  • Venus is associated with a corporate entity referenced in its Terms of Service (e.g., for hosting, liabilities, and user agreements). Exact legal name, jurisdiction, registration number and directors are Not verifiable as of 2026‑08‑29.
  • Use of the app is governed by Venus’s Terms of Service and risk disclosures, which place most risk on users and reserve broad rights for the operator. ### Overall assessment Control over contracts, frontend and key funds is effectively company/council‑controlled with a governance token layer that can influence but likely does not fully override core operator control.
Evidence (2)

legal & regulatory

two sources

Venus Core Pool is part of the Venus Protocol, a lending/borrowing protocol on BNB Smart Chain (BSC). On‑chain verification via Dune is not available in this run; all facts below are from off‑chain sources only and any on‑chain aspect is Not verifiable as of 2026‑08‑29. 1. Legal entity / jurisdiction

  • Venus is closely tied to the Venus Prime Foundation Ltd., incorporated in the British Virgin Islands (BVI), referenced in governance and documentation for the XVS token and Venus Prime program.
  • The original development was strongly associated with Binance Smart Chain ecosystem and at points with the Swipe/Venus team, but there is no clear, current, centralized operating company publicly positioned as “Venus Core Pool operator”.
  • From a risk view, this suggests a foundation‑plus‑DAO style governance with significant decentralization claims, but ultimate enforceability of rights may depend on BVI law over the foundation and potentially other, undisclosed contributors. 2. Terms of Service / user restrictions
  • Venus front‑end access is provided via web interfaces that include standard DeFi disclaimers: use at your own risk, protocol may be governed by token holders, and services are not directed at restricted jurisdictions (often including U.S. persons and sanctioned countries).
  • Exact ToS language, governing law, and jurisdiction clauses differ by interface and are not consistently centralized; some interfaces are operated by third‑party front‑end providers. Precise ToS coverage for Venus Core Pool specifically is Not verifiable as of 2026‑08‑29. 3. KYC / AML
  • The underlying Venus smart contracts on BSC are openly accessible; there is no protocol‑level KYC on the core pool contracts.
  • Any KYC/AML control would be at the front‑end or access‑layer level (e.g., geo‑blocking, IP filters), not on‑chain. The effectiveness and scope of such controls are Not verifiable as of 2026‑08‑29. 4. Regulatory classification & disclosures
  • Venus Protocol is generally categorized by analytics and research providers as a DeFi lending/borrowing protocol using over‑collateralized loans on BSC.
  • There is no public designation by a major regulator (SEC, CFTC, ESMA, HK SFC, MAS, etc.) that clearly classifies Venus or its XVS token as a specific regulated instrument (e.g., security, derivative). No formal prospectus or regulated offering documentation is evident. 5. Warnings, enforcement, court cases, sanctions
  • No major public enforcement actions or formal regulatory warnings specifically targeting Venus Protocol or “Venus Core Pool” were identified in recent searches (U.S., EU, UK, Singapore, HK regulators) as of 2026‑08‑29.
  • No OFAC or other sanctions‑list inclusion for Venus‑specific entities was found.
  • Absence of evidence is not evidence of absence: regulators have increasingly taken action against similar DeFi lending protocols; this residual risk should be considered non‑trivial. 6. Data protection & user data
  • Core smart contracts do not process personal data beyond wallet addresses. Any personal data (IP logs, email, KYC if used by some interfaces) would be collected by front‑end operators and subject to their own privacy policies, not a unified “Venus” framework. These policies and their GDPR/CCPA alignment are Not verifiable as of 2026‑08‑29.
Evidence (4)

Stability

stability

two sources

Not verifiable as of 2026-08-29. The provided search results do not identify with confidence which stablecoin underlies the Venus Core Pool on BSC, so I cannot reliably determine whether it ever depegged, how many times, the last occurrence, or the depeg percentage. The results only show general stablecoin depeg examples and unrelated or potentially mismatched Venus Core Pool pages; one source mentions USDT in Venus Core Pool, while another mentions USDC, but neither is sufficient to confirm the pool’s actual stablecoin exposure for the question asked. If you want, I can next verify the exact underlying stablecoin for the BSC Venus Core Pool and then check historical depeg behavior from independent market data.

Evidence (3)

Risks & Strengths

risks

two sources

For Venus Core Pool on BSC, the top 5 risks are: (1) smart contract logic risk, because third-party reviews and incident writeups show exploitable contract-path assumptions in core-pool code; (2) oracle / pricing risk, since Venus itself and Code4rena findings highlight stale or zero-price handling and price-dependent liquidation behavior; (3) collateral / liquidity risk, because the core pool aggregates many assets and Venus notes that a volatile token can threaten the pool’s overall liquidity; (4) liquidation and high-volatility risk, because under-collateralized positions can be liquidated automatically and liquidation cascades are an explicit concern; and (5) governance / parameter risk, because listing new assets, setting caps, and tuning risk parameters can introduce systemic risk if misconfigured. The strongest concrete evidence is the March 2026 BSC donation-attack incident, which shows that a core-pool supply-cap/control assumption could be bypassed and lead to millions in borrowed assets. Additional context: Venus’s own repository says the Core Pool “aggregates a diverse group of assets,” that extreme volatility in one listed token can create significant liquidity risk for the whole protocol, and that the Core Pool lacks some shortfall-analysis parameters that would improve market-stability visibility. Independent incident coverage also reports two security incidents and about $4.6M in losses, which reinforces that historical exploitability is not theoretical. Third-party risk summaries also point to smart-contract vulnerabilities, oracle failures, and liquidation cascades as recurring DeFi-lending failure modes. Not verifiable as of 2026-08-29: exact current TVL, incident-adjusted loss rate, and any on-chain chain-specific exposure breakdown, because on-chain verification is unavailable in this run.

Evidence (5)

strengths

two sources

Venus Core Pool’s main strengths are: large liquidity and established scale, broad asset support on BNB Chain, core lending/borrowing utility, dynamic interest-rate design, and BSC-native low-cost execution. DefiLlama and other trackers describe it as a major lending market on BNB Chain, while Venus’s community and docs emphasize that the Core Pool is the backbone of its lending ecosystem and supports a diverse set of assets with supply/borrow interest mechanics.

  • Scale / liquidity depth: multiple independent trackers place Venus Core Pool in the roughly $1B+ TVL range, indicating substantial liquidity and market depth for borrowers and suppliers.
  • Core lending utility: it is the protocol’s primary market for supplying assets, borrowing against collateral, and earning interest, which makes it the central product rather than a side feature.
  • Broad asset coverage: sources describe support for a wide range of BEP-20 assets and multiple supported markets, which improves capital usability and makes the pool more versatile for users.
  • Liquidity and borrowing efficiency: Venus community discussions explicitly note that moving assets into the Core Pool can improve liquidity and borrowing conditions, suggesting the pool’s design is optimized for efficient capital access.
  • BSC advantage: because Venus Core Pool runs on BNB Chain, users benefit from low transaction costs and fast settlement relative to higher-fee chains, which is a practical strength for lending activity. A secondary strength is mature protocol infrastructure: third-party reviews and data platforms note audits, long operating history, and established governance mechanisms, which can be positive signals for institutional users.
Evidence (9)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 24 fact categories not yet collected.
  • Fact verifiability: 20 two independent sources, 4 one source, 5 unverified.
  • Oldest fact verification date: 2026-08-29.