Sui's Volo Protocol Loses $3.5M to a Leaked Key, Then Recovers Nearly All of It
On April 21, 2026, roughly $3.5 million left Volo, a liquid-staking protocol on Sui, drained from three isolated vaults holding WBTC, XAUm (tokenized gold), and USDC. Volo's own statement was blunt about the cause: no smart contract had malfunctioned. A private key had simply ended up in the wrong hands, and everything that followed was the protocol behaving exactly as that key instructed.
The timing meant the incident landed quietly. Three days earlier, KelpDAO had lost $290 million in a LayerZero-bridge exploit, and most of the industry's researchers, journalists, and on-chain analysts were still absorbed in that story when Volo's breach surfaced.

What made Volo's case unusual wasn't the exploit but the response. No researcher had flagged anything suspicious beforehand, and no monitoring service had issued a warning. Volo disclosed the breach itself, before anyone else knew there was a story to tell. Within hours the team had frozen its remaining vaults, notified the Sui Foundation, opened an investigation, and committed to covering losses from its own treasury rather than passing them on to users.
Thirty minutes after that initial post, a follow-up update confirmed that $500,000 of the stolen funds had already been frozen through coordination with ecosystem partners. By the time QuillAudits published its own analysis, Volo said it had already clawed back $2 million and intercepted 19.6 WBTC the attacker had tried to move.
Attribution and technical findings
The attacker's Sui wallet has been identified as 0xd763599972ea5a8cfe53d182371ee010dc52ace7e39ccff7d8803ba7100fa46a. Two transactions carried out the drain: 7pTrudZb57z2acJFvC2CnBCuaU6RA1UpU9auDZQEESit and AQw9wMFfxSpDoF6YAfDhPLvKbdGSkxbGkc1DnZb43RUS. The compromised admin account has been traced to 0xe76970bbf9b038974f6086009799772db5190f249ce7d065a581b1ac0adaef75.
SlowMist classified the incident without ambiguity: Private Key Leakage. Three separate firms — GoPlus Security, ExVul, and Bitslab — published independent on-chain breakdowns within 48 hours, and each reached the same conclusion: the contracts themselves were sound, the audits hadn't failed, and the single point of failure was a leaked credential. QuillAudits' independent write-up didn't appear until April 23, roughly a day and a half after Volo's own disclosure — not because the analysis was slow, but because attention across the industry was still fixed on the KelpDAO fallout.
Tracking the stolen funds across chains
Within hours of the theft, the attacker moved close to $1.55 million in USDC off Sui and onto Ethereum, spreading it across six transactions inside an eighty-minute window and routing it through Circle's Cross-Chain Transfer Protocol to an Ethereum address ending in Af1ca.
That same bridge infrastructure had drawn criticism three weeks earlier during the Drift Protocol exploit, when $230 million in stolen USDC moved from Solana to Ethereum across more than 100 transactions in broad daylight without Circle freezing any of it — a failure ZachXBT criticized publicly at the time. This time the outcome differed not because Circle reacted faster, but because Volo's coordination with exchanges, swap services, and KYT compliance tools got the attacker's Ethereum address flagged across most of the ecosystem before the exit window closed.
The larger recovery happened on the Bitcoin side. An attempt to bridge all 19.6 WBTC off-chain was blocked, and those funds are now held by ecosystem partners while Volo works out how to return them — the single largest intercept of the entire episode, achieved before most of the industry had even registered that Volo had been hit.
The $1.55 million in USDC that reached Ethereum didn't stay there either. Recovery Update #4 later confirmed that 90% of the funds that had left Sui — including that USDC — were converted to ETH, swapped back into stablecoins, and bridged home, turning the attacker's Ethereum wallet into a dead end rather than a successful exit. Combined with the roughly $500,000 frozen within hours of the attack, the WBTC intercept, and additional funds recovered in ETH across two further updates, Volo clawed back nearly the entire $3.5 million — a recovery that depended entirely on the team not waiting for anyone else to sound the alarm.
Reaction across the Sui ecosystem
Even before the investigation wrapped up, other Sui protocols acted defensively. NAVI Protocol, one of the network's larger lending platforms, paused its contracts and activated security procedures within hours of Volo's announcement, despite not being touched by the exploit. NAVI confirmed it was unaffected and restored deposits and withdrawals about six and a half hours later.
Matrixdock, issuer of the XAUm token, confirmed that the physical gold reserves backing the token — audited by Bureau Veritas — remained fully intact; the exploit had compromised the on-chain token, not the underlying vault. In a subsequent post, Matrixdock said that after verifying the exploit, it had frozen the remaining XAUm still sitting in the attacker's wallet. SuiLend also reported normal operations, with no contagion spreading to other protocols. Volo itself noted that no shared attack vector existed across its unaffected vaults — the same vault isolation that concentrated the initial damage also kept it from spreading further.
Outside the Sui ecosystem, the incident drew little notice. April 2026 had already produced KelpDAO's $290 million loss, Drift Protocol's $285 million exploit, an $18.4 million margin-trading manipulation at Rhea Finance, and a $2.5 million forged-proof exploit at Hyperbridge. By the time Volo's numbers were finalized, some estimates put April's total DeFi losses above $600 million, leaving little room for a comparatively small, well-handled incident to lead the news cycle.
Final recovery figures

Four days after the attack, Volo's Recovery Update #4 reported that the perpetrator had been identified and the damage contained. Three days later, Recovery Update #5 added the recovery of roughly 64.9 more ETH, bringing the net loss down to about $60,000, with every vault except XAUm cleared to resume normal operations.
Of the original $3.5 million taken, approximately $3.44 million was ultimately recovered — through the WBTC intercept tied to the LayerZero bridge, 100.6 XAUm returned to custody via the Sui Foundation, and the 90% of stolen funds that came back in ETH before being converted to stablecoins and bridged back to Sui. The remaining 115 XAUm that the attacker had already sold off is set to be fully reminted through Matrixdock's minting process. The resulting net loss of about $60,000 will be absorbed entirely by Volo's treasury, with nothing passed on to users.
What comes next
A full "back to business" plan from Volo is still pending. The identified perpetrator has not been named publicly, and the affected vaults remain frozen until that plan is released. What won't change once it lands is the root cause: three prior audits and an active bug bounty program did nothing to stop this, because neither is built to catch a compromised individual. Two and a half years of clean operation gave no warning either. A single key, once in the wrong hands, was enough — and per Chainalysis, private key compromises already accounted for the largest share of crypto stolen in 2024, and for 88% of losses in the first quarter of 2025. The pattern is well documented; protocols keep encountering it regardless.
Sources: Volo, The Block, QuillAudits, SlowMist, GoPlus Security, ExVul, Bitslab, Bitcoin.com News, ZachXBT, NAVI Protocol, Matrixdock, SuiLend, BankInfoSecurity, Yahoo Finance, Chainalysis.
Get new scam files the moment we publish them — usually 2–3 emails a week.