[One Night of Horror] How I Almost Lost $13M in the Venus Phishing Attack
People often say there’s nothing sweeter than realizing a disaster was just a scare. But you’ll never understand the weight of those words until you come within inches of losing everything.
On September 2, 2025, I came terrifyingly close to losing $13 million in my wallet within just a few hours.
It was a phishing attack carried out by the infamous Lazarus Group.
If not for the incredible response of several security teams, this story would not have ended with relief — it would have ended in tragedy.
Here’s my account of what happened, from the victim’s perspective.
1. How It Started: An Innocent-Looking Meeting
I first met someone claiming to be Stack’s Asia BD back in April 2025 at the Wanxiang Conference in Hong Kong. A friend introduced us in person, and later another friend connected me with someone else from Stack, saying they might be interested in working together. We exchanged contacts on Telegram and stayed loosely in touch.
On Friday, August 29, this Asia BD asked me to join a “catch-up” call at 11:00 PM. Because my previous meeting ran late, I joined around 11:10 PM. He told me it was fine.
The meeting link he sent was for Zoom. At the time, I didn’t think much of it. Looking back now, Zoom has become a favorite weapon of Lazarus in social engineering attacks (see this Huntability report: link).
2. The Trap: A Simple “Upgrade”
Because I was late, I felt guilty about making people wait. That guilt made me careless.
Once I joined the Zoom call, I saw what looked like him and several “colleagues” on video — but there was no audio. Then a pop-up appeared: “Your microphone isn’t working, please upgrade.”
Already flustered from being late, I just wanted to fix the issue quickly and not waste anyone’s time. Without thinking, I clicked upgrade.
That was the trap.
3. A Tailor-Made Attack
This wasn’t random. Later I realized it was a highly targeted and customized attack.
Days earlier, the attackers had already deployed a malicious contract perfectly tailored to my positions. Most of my assets were deposited in Venus, with large amounts borrowed — making my setup unusual. From Venus’s official report, you can see how complex the attacker’s single transaction was, clearly designed for my account.
They must have studied my habits. Knowing I often used Rabby wallet, they likely created a fake Rabby plugin to replace my Chrome extension.
Here’s what happened:
That day my Chrome crashed unexpectedly when I opened my laptop. It asked if I wanted to “restore tabs.” I clicked yes.
In the restored tabs, I opened Venus and performed an action I had done thousands of times: withdraw.
Normally, Rabby’s excellent risk controls would have flagged unusual contract calls, shown me a simulation, and asked for extra confirmation.
But because the plugin had been swapped with a fake, none of that appeared. The transaction went through smoothly — too smoothly.
That familiarity lulled me into a false sense of safety. It felt just like every other withdrawal I had ever done. And that’s exactly why I didn’t catch it.
Moments later, Chrome crashed again. My computer froze, my Google account was logged out, and when I checked my wallet, the USDT I thought I had withdrawn wasn’t there. Instead, I saw an abnormal transaction. My stomach dropped.
Later, I learned from a friend that this “Asia BD’s” Telegram account had already been compromised long ago. In other words, I had been speaking to an impostor the whole time.
That’s the scariest part:
If it had been a stranger, I would have been cautious.
If it had been a close friend, I would have noticed differences in behavior.
But it was someone “half familiar,” with enough background setup to lower my guard — and that’s exactly what made me vulnerable.
4. The Truth: Fake Identities, Deepfakes, Lazarus
Based on the method, the gas sources, and similar cases, it became clear this was the work of Lazarus Group.
The “colleagues” I saw on the Zoom call were most likely deepfake-generated faces.
I later heard that months earlier, a Venus community admin had fallen victim to almost the exact same trick: a Zoom phishing meeting that drained their Venus funds. In their case, the money was never recovered.
5. The Turning Point: Emergency Response
The moment I realized what had happened, I contacted PeckShield.
Dr. Jiang immediately created a chat group connecting me with the Venus team.
I had never spoken to the Venus team before. Yet, upon seeing the abnormal transaction, they made the boldest move: pausing the protocol.
Why? Because the transaction was clearly suspicious:
My account contained five types of collateral and large borrowings.
The attacker used delegate approval to bundle everything into one massive transfer.
It looked nothing like normal user behavior.
Pausing the protocol, auditing the contracts, checking for possible frontend hijacks — these were all necessary steps. Thanks to their quick action, Lazarus was stopped before they could fully cash out.
6. Reflection: Lessons Learned
This incident shows how far Lazarus has evolved: social engineering + deepfake video + technical trojan combined into one.
Even seeing someone on video or checking their Twitter profile doesn’t guarantee they’re real.
And here’s the painful truth:
I was using a hardware wallet. It’s supposed to be the gold standard of security. But because DeFi interactions often require blind signing, the attackers exploited the weakest link: the frontend.
With the fake Rabby extension, everything looked normal.
My hardware wallet executed the signature faithfully — but the underlying data was malicious.
The “security wall” crumbled because the input had already been poisoned.
It taught me this harsh lesson: a hardware wallet is not a magic shield. If the frontend is compromised, blind signing can still kill you.
7. Takeaways: My Advice for Others
Avoid Zoom: Lazarus has repeatedly used it as a phishing vector. Don’t use it for sensitive meetings.
Plugins only from official stores: Never click “upgrade” links in pop-ups.
Use hardware wallets — but stay alert: They’re essential, but not foolproof if the frontend is malicious.
Don’t trust “half-familiar” people: Deepfakes make impostors look convincing. Be skeptical.
Pause before clicking: Even a “microphone upgrade” request can be the start of an attack.
Final Thoughts
This felt like a direct battle with Lazarus.
In the end, with the help of @VenusProtocol , @peckshield , @binance ,@chaoslabs , @hexagate_ , @HypernativeLabs , @SlowMist_Team and others, we didn’t just lose less — we won back control.
But I know the truth: most people who face Lazarus never get their assets back. I was incredibly lucky.
And I’ll never forget the lesson:
In crypto, the biggest danger isn’t volatility.
It’s the moment you think, “this looks normal.”
3/3 🧵
As we prepare for KBW 2025, we're seeking partners. If you're a project interested in a Go-to-Market strategy in Korea, let's connect! Our DMs are always open.
1/3 🧵
We had an incredible time at @gmvn_official 🇻🇳, experiencing the vibrant crypto scene in Southeast Asia! We saw lots of exchange sponsors and learned locals favor futures trading on CEXs over on-chain activities.
2/3 🧵
It was great to see diverse crypto sessions, including a focus on BTCfi. We also saw active Meme token trading, which showed us promising growth opportunities beyond the traditional Game-fi market.
It’s here: Finance that just flows
You deserve a real shot at building wealth
With just $1
On premium options
In one click
And so we start our mission with Grvt Strategies — now LIVE
Invest in elite traders and let them win for you
Plus, get early time-limited rewards:
1. Invite friends to invest & earn up to 500 USDT each
2. Invest & get guaranteed extra 20% APR
→ Time-limited incentives details: https://t.co/AHyVHG3awO
→ Base incentives details: https://t.co/Iv06rivXtM
→ Invest in our first lineup of traders now: https://t.co/LXiTV51KWJ
And spot our new look?
Vision, mission, roadmap, and our brand upgrade details coming soon. Stay tuned.
We’re proud to announce that we’ve closed a $1.5M strategic round including @mirana, @caladanxyz, @zokuventures, and a small number of other key partners.
To welcome Omni’s next phase of growth on @arbitrum, we’ve now opened the referral program to all users.
1/
$DOOD will be launching on Solana 🔜
we’ve optimized for a smooth experience and will be airdropping $DOOD to eligible communities, whether you’re a current Doodles NFT holder or a New Blood community member.
here's how to get your airdrop ↓