Sui-Based Volo Suffers $3.5 Million Exploit, Pledges to Cover All Losses
Volo is a BTCFi and liquid-staking protocol built on the Sui network. It offers SUI staking and yield-generating vaults for assets including WBTC, XAUm and USDC. The incident affected several major crypto assets and tokenized real-world assets, underscoring the importance of asset-management permissions and vault isolation in DeFi protocols.
On April 21, 2026, vulnerabilities were exploited in Volo’s WBTC, XAUm and USDC vaults, affecting about $3.5 million in assets. The team immediately notified the Sui Foundation, froze all vaults and intercepted about $500,000 in assets within half an hour. The remaining roughly $28 million in total value locked remained secure. Volo pledged to absorb all losses itself rather than pass them on to users.
All Coverage
4 original reportsThe Backstory
The history behind this eventSui DEX Aftermath Hacked for $1.14 Million in USDC
Aftermath Finance is a decentralized exchange in the Sui blockchain ecosystem whose perpetual futures product lets users trade crypto assets with leverage. The security incident involved its transaction-builder fee mechanism, highlighting the risks that emerging onchain derivatives protocols face in fee calculations and permission validation. It also directly affects user funds and market confidence.
Aftermath Finance’s perpetual futures product was hacked on April 29 after an attacker exploited a vulnerability in its “builder code fees” mechanism and drained about $1.14 million in USDC from the protocol. The team paused the affected product after detecting the anomaly to prevent further losses and said it would fully reimburse all affected users. A timeline for fixing the vulnerability and paying compensation has yet to be announced.
Sui DeFi Protocol Scallop Hacked for 150,000 SUI Through Legacy Contract Flaw
Scallop is a DeFi lending protocol on Sui that offers asset deposits, borrowing and an sSUI rewards pool. The incident highlights how deprecated contracts may remain directly callable. Without version restrictions, legacy code can expose funds to risk even when the core market is unaffected.
On April 26, 2026, an attacker exploited a legacy V2 rewards contract deployed in November 2023. By taking advantage of an uninitialized last_index, the attacker claimed about 20 months of accrued rewards and stole roughly 150,000 SUI, then worth about $142,000. Scallop immediately froze the contract and resumed operations within about two hours. It said the core protocol and user funds were safe and that it would cover the loss in full.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.