iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Venus documents several ways governance can change the Core Pool, but proposal delays are only one part of its control surface. Voting power, function-level permissions, timelock execution and guardian pause powers are separate mechanisms. A March 2026 proposal says a direct-token-donation exploit in the BNB Chain THE market caused about $2.15 million in bad debt; it describes an accounting patch, but does not by itself establish that the patch was deployed everywhere or that borrowing has resumed on every affected market.
How Venus governance can change the Core Pool
Venus describes governance as a chain of distinct authorities, rather than a single vote that directly changes protocol contracts. XVS locked in XVSVault supplies voting power, which holders may delegate. GovernorBravoDelegate manages the proposal and voting lifecycle; a successful proposal is queued for execution through a Timelock. Separately, AccessControlManager (ACM) grants or revokes permission to call specific contract functions.
This separation matters when assessing risk. A vote may authorize a change, but the route’s delay governs when queued actions can execute; ACM permissions govern who or what can call privileged functions; and guardian controls provide a separate way to pause specified market actions. A review of the governance attack surface should examine all of these paths on the specific chain, not just the time between a vote and execution.
Free tools Windows power users keep installed
One-click scans. No signup required.
What each control layer does
| Layer | Documented role | What it does not establish by itself |
|---|---|---|
| XVSVault and voting delegation | XVS locked in XVSVault provides voting power; voting power may be delegated. | Documentation alone does not show how voting power is currently distributed or who controls it. |
| GovernorBravoDelegate | Handles proposal stages and voting. | A proposal vote is not proof that a particular contract permission or deployment changed. |
| AccessControlManager | Manages permissions to call specific contract functions, including granting and revoking permissions. | A published contract address does not reveal the current permission state. |
| Timelock | Queues successful proposals and controls their delayed execution. | A documented delay does not prove that a timelock currently has authority over a given action. |
| Guardians | Can pause fine-grained actions on individual markets, according to Venus’s governance documentation. | This should not be read as evidence that every guardian can pause every action on every chain, or that a market is currently paused. |
What are Normal, Fast-track and Critical VIP routes?
Venus’s governance documentation describes three routes with different voting windows and post-vote delays. The figures below are documentation values, not a live reading of on-chain configuration. The documentation also describes additional execution delays for commands outside BNB Chain but does not give a single cross-network delay value in the material summarized here.
#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
| Route | Documented voting window | Documented post-vote delay | Documented use or authority caveat |
|---|---|---|---|
| Normal | 24 hours | 48 hours | Described for more consequential actions, including upgrades and access-control changes. |
| Fast-track | 24 hours | 6 hours | Described for risk-parameter changes. The route shortens the delay compared with Normal; it does not make the ACM or guardian control paths irrelevant. |
| Critical | 6 hours | 1 hour | Venus’s decentralization page says that since VIP-645 the Critical Timelock has no permission on any network and can no longer execute privileged actions. The nominal timing therefore should not be mistaken for currently available authority. |
These values explain the intended speed-versus-review trade-off, but not the full effective security boundary. Current proposal thresholds, voting-power distribution, ACM permissions, timelock settings and guardian authority need to be checked against the relevant chain and contracts. Venus publishes deployed-contract addresses, including governance-related contracts, but an address list is not proof of current storage values or permissions.
Can Venus guardians pause a market?
Venus documents fine-grained pausing: guardians can halt individual actions on particular markets, rather than necessarily stopping the whole protocol. This is an emergency-control path distinct from ordinary proposal voting and timelock execution. The distinction is useful during an incident because it allows a narrower response than a protocol-wide halt, but the documentation’s description should not be treated as confirmation of a particular guardian’s present permissions or a market’s current status.
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide (4.9 App Store, 4.8 Google Play) - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
To assess a live case, identify the chain and market, the precise action to be paused or resumed, the guardian contract or account with authority, and the current permission state. A general statement that “guardians can pause” is not enough to establish whether a specific borrow, supply or other action can be stopped at that moment.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →What happened in the March 2026 THE market donation attack?
A Venus Community proposal dated March 20, 2026, describes an attack on the BNB Chain THE market on March 15. According to that proposal, an attacker transferred more than 36 million THE directly to the vTHE contract instead of using the normal mint flow. The proposal says the contract’s reported cash was derived from the underlying token balance, so the donation distorted the market exchange rate by approximately 3.8 times and bypassed supply-cap enforcement. It reports that the resulting conditions supported borrowing assets including CAKE, USDC, BNB and Bitcoin, and led to approximately $2.15 million in bad debt. These amounts and causal details are the proposal’s reported account, not independently verified figures.
Rank #3
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
The described exploit was a vToken cash-accounting weakness. It does not, on its own, show that an attacker took over Venus governance, manipulated a vote or compromised a timelock. Governance is relevant to who can authorize an upgrade, which permissions support deployment, who can pause affected actions and how remediation is executed; those are related but different questions from the technical cause of the donation exploit.
What patch did the proposal describe?
The proposal says the prior _getCashPrior() logic derived cash from the underlying token’s contract balance. Its proposed replacement uses an internally tracked internalCash value, updated during protocol transfer-ins, transfer-outs and bad-debt recovery operations. The proposal also describes an access-controlled syncCash() step to initialize the internal accounting after an upgrade.
Rank #4
- EAL5+ CERTIFIED SECURE ELEMENT + FINGERPRINT PROTECTION — Your private keys stay encrypted offline on a certified EAL5+ chip, the same security tier used in EMV bank cards. Built by DCENT, securing crypto since 2018. Fingerprint authentication adds a second layer no PIN-only wallet can match.
- 10,000+ ASSETS NATIVE ON 100+ BLOCKCHAINS — Hold Bitcoin, Ethereum, XRP, Solana, Cardano, popular stablecoins (USDT, USDC), and NFTs in one wallet. No third-party apps, no fragmented setup — every supported asset works straight out of the box.
- TAP-TO-SIGN MOBILE EXPERIENCE — Pair your wallet with the DCENT mobile app over Bluetooth. Manage tokens, review transactions, and access in-app swap features directly from your phone — no cables, no desktop required.
- WEB3 & dAPP ACCESS VIA METAMASK — Connect to MetaMask and other browser extension wallets to manage NFTs, claim airdrops, and access dApps. A large screen and intuitive 4-button interface keep every transaction clearly visible before you sign.
- SEAMLESS FIRMWARE UPDATES & 30-DAY MONEY-BACK GUARANTEE — Apply security updates without resetting your wallet or migrating funds. Backed by Amazon's 30-day money-back guarantee — your purchase is risk-free.
That design aims to prevent unsolicited token transfers from being counted as protocol cash in the same way as assets moved through the normal accounting flow. But the proposal is a description of intended remediation, not an execution receipt. It describes one BNB Chain deployment and patches for seven named non-BNB Chain networks, as well as resuming borrowing there after patching. It does not establish that every proposed upgrade and synchronization completed, or that every named market is now unpaused.
What would establish deployment?
- An executed governance action or other authoritative deployment record for each relevant network.
- Contract or chain-state evidence that the upgraded market uses the proposed accounting and that initialization was completed.
- Evidence of the market’s current pause state and whether borrowing was resumed.
Without those checks, the accurate answer to “Was the patch deployed?” is that the March 20 proposal describes the patch and intended network actions, while the proposal alone does not confirm completed deployment across all listed networks.
Best Value
- Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
- Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
- See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
- Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
- Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
What does this incident reveal about governance accountability?
The proposal thread discusses an attack class that had previously been identified and why it was not prioritized. That discussion is relevant context, but it is not a complete authoritative account of risk acceptance, decision-making or individual responsibility. It does not support assigning blame to a particular person or process without a stronger record.
A useful accountability review keeps three questions separate: what the technical flaw was; what governance and emergency mechanisms were available and exercised; and who made which risk or prioritization decisions. The available proposal documents the incident claims and a remediation plan, but does not settle the full internal decision history.
How should audits and public contract listings be interpreted?
Venus’s Security & Audits page lists Core Pool BNB Chain E-Mode audit reports from CertiK dated September 19, 2025, and Quantstamp dated September 3, 2025. Those listings establish that reports with those dates and scopes are published; they do not establish that the reports covered the March 2026 incident, the proposed internalCash patch, or every governance permission path. Assessing coverage requires matching each report to its stated scope, reviewed code and findings.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Venus also says contract code and balances are publicly verifiable, lists a bug bounty program and advises users to make independent assessments of security and suitability. Public verifiability can support an on-chain review, but it does not replace checking actual permissions and configuration on the chain being discussed.
Quick Recap
A practical way to assess Venus governance risk
- Fix the scope. Name the chain, Core Pool market, contract function and action under review. Do not infer one network’s state from another’s.
- Check the voting path. Confirm the applicable proposal route and current voting configuration, rather than assuming the documentation’s timing values remain unchanged.
- Check execution authority. Verify the relevant Timelock and ACM permissions on-chain, including whether the timelock can execute the specific privileged function.
- Check emergency controls. Establish which guardian can pause or resume the specific action on the market and inspect the current pause state.
- For the THE remediation, verify each deployment step. Confirm the patch version,
internalCashinitialization, and borrow status for each affected chain and market before concluding the issue is remediated.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

