CryptoReal
CASE FILE — Jun 5, 2025

How Vesu Caught and Patched a Starknet Lending Flaw Before Anyone Could Exploit It

Not every DeFi security story ends with a drained treasury. Vesu, a lending protocol built on Starknet, identified a critical vulnerability, disclosed it, and shipped a fix — all without losing a single dollar of user funds or receiving a ransom demand from an attacker.

A researcher operating under the handle Alex found the underlying flaw before anyone could weaponize it, and chose to report it through Immunefi's bug bounty program rather than build an exploit around it. Five days later, Vesu had migrated its entire protocol to a patched version, secured all user funds, and published a complete public disclosure — without the usual pattern of social-media panic or emergency governance votes that typically follows a DeFi security scare.

The flaw itself was a rounding error capable of being exploited for outsized gains, but it was caught, remediated, and disclosed before it ever affected a user.

Vesu's disclosure, the Immunefi announcement, and Vesu's own statement lay out how the process unfolded.

Timeline of the disclosure

Alex identified a rounding-convention bug in Vesu's liquidation logic on May 23rd and reported it through Immunefi's bug bounty program for Vesu rather than attempting to exploit it. Immunefi escalated the report to Vesu's team within hours. By that same afternoon, Argent's security team had joined to assess the issue technically, followed shortly by ChainSecurity.

Per Vesu's disclosure report, actually exploiting the bug would have required deploying a malicious pool extension and pairing it with flashloans. There is no indication the technique was ever used before Alex reported it — but the potential for damage was real.

What the bug actually was

The flaw lived inside the Singleton::liquidate_position function, specifically in logic tied to the receive_as_shares flag — a feature that allowed liquidators to be paid out in pool shares rather than underlying assets whenever a pool's liquidity had been exhausted. On its own, the mechanism served a legitimate purpose. Combined with a maliciously crafted pool extension, however, it opened a path for an attacker to manipulate the rounding math and mint shares worth more than what they had deposited — effectively creating value from nothing.

The root cause traced back further, to Vesu's permissionless pool-creation design: anyone could deploy a pool with custom lending hooks, a feature intended to encourage flexibility and innovation but one that also widened the attack surface considerably.

The response

Vesu's team had a remediation plan in place within 24 hours of receiving the report. By May 27th, the fix was ready to deploy: migration contracts had been written, backend updates prepared, and frontend changes staged.

Rather than trying to patch the vulnerable feature in place, the team removed the receive_as_shares mechanism from the protocol entirely. To address the broader permissiveness problem, they whitelisted which pool extension contracts could be deployed, preserving the permissionless model in spirit while closing off the specific attack path. The new contracts were also made upgradeable via a 3-of-5 multisig that includes external signers, giving the team a way to correct course if problems emerged during migration.

Migration began at 1 PM on May 28th, coordinated with ChainSecurity, Argent, Immunefi, and several lending-pool curators, including Re7 Labs, Braavos, and Alterscope. By 10:30 PM that evening, the migration was complete, verified, and publicly announced.

In total, five days elapsed between the initial bug report and a fully patched, migrated protocol.

Why this matters

Asked about its approach to security, Vesu described its bug bounty program as one piece of "a continuous, multi-faceted process," alongside audits and ongoing monitoring — rather than treating any single measure as a guarantee against exploits. That framing matches what was already in place before this incident: an active Immunefi bug bounty, standing security relationships with ChainSecurity and Argent, and multiple auditors and pool curators reviewing the codebase on an ongoing basis.

When Alex's report came in, that structure functioned as intended: a bounty hunter flagged an issue, security partners were assembled quickly, a fix was designed, tested, and deployed, and a full disclosure followed — without an emergency DAO vote, a public scramble, or threats of legal action.

Incidents like this rarely attract the same attention as an actual exploit, simply because there is no loss to report. But cases where a vulnerability is caught and resolved before it causes harm likely occur more often than the headline-grabbing failures that dominate DeFi security coverage — they just don't generate the same level of public interest, since nothing appears to have happened. In an industry where most security conversations start only after funds are already gone, Vesu's handling of this bug is a reminder of what a functioning process, exercised in advance rather than in response, actually looks like.

Bug BountiesDefiVesu
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.