← Radar

Incident case file

Sign in to watch

Volo Protocol — Admin Private Key Compromise (Sui Vaults)

Incident date April 22, 2026

0 views

ResolvedSuiPrivate key leakCluster: VOLO-SUI-2026-04

Estimated loss

$3.5M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

95%

Facts and investigation

Attacker: Not publicly disclosed (tracked by ZachXBT)

Funds moved to: Attempted LayerZero bridge to Ethereum (19.6 WBTC intercepted). Some assets swapped to USDC on Sui → bridged to Ethereum → converted to ETH (recovered). 115 XAUm sold on Sui (recreated by Matrixdock).
Compromised vaults: WBTC vault, XAUm vault, USDC vault. ~$28M TVL in unaffected vaults secured throughout.

Timeline: April 21, 2026 — Vault admin private key compromised (operational failure, not a smart contract bug). Attacker calls withdraw_with_account_cap_v2 to drain WBTC, XAUm, and USDC vaults. April 22 — Volo announces publicly, freezes all vaults, notifies Sui Foundation and ecosystem partners. ~$500K frozen within 30 minutes. 19.6 WBTC (~$2.1M) intercepted on LayerZero bridge attempt. April 25 — Volo confirms 90% of funds recovered. April 26 — Final recovery update: 64.9 ETH recovered. Net loss: ~$60K, fully absorbed by Volo. No user suffers a net loss.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)