Volo, a BTCFi and liquid staking (LST) protocol on the Sui network, disclosed a critical security vulnerability early on July 22. Approximately $3.5 million in crypto assets — including WBTC, XAUm, and USDC — was stolen from three specific vaults.
Three Vaults Compromised, $28M TVL Remains Safe
According to Volo's official statement, the attack vector targeted only three particular vaults, with no identical exploit path found in the rest of the protocol. The team confirmed that the remaining $28 million in total value locked (TVL) is secure. Affected vaults have been frozen to prevent further losses.
Volo operates as a dual-function protocol in the Sui ecosystem: it facilitates Bitcoin-related assets in DeFi (BTCFi) and offers liquid staking services, allowing users to stake assets for yield while receiving tradable LST certificates. Such protocols typically manage multiple strategy vaults with distinct asset mixes and risk parameters. This incident suggests the attacker precisely identified vulnerable vaults.
Team to Bear Losses, User Funds Protected
Volo stated it will fully absorb the financial hit, pledging not to pass any loss onto users. A comprehensive post-mortem and remediation plan will be released once investigations conclude, detailing the root cause and future security enhancements.
We solemnly declare: Volo is prepared to bear this loss. We will do our utmost to avoid any impact on users.
We are currently undergoing crisis management. Once that concludes, we will devise a remediation plan and disclose the full plan as soon as possible.
No details about the attacker's method or exploited vulnerability have been disclosed yet. Security teams are investigating, and a detailed technical analysis is expected to follow. The event has reignited discussions on the security of cross-chain staking protocols.

