AltCoins Analysis

Altcoins Meet Analysis Here

IOTA News: Virtue Implements “Plan B” Recovery Following August Oracle Manipulation Attack

IOTA

DeFi protocol Virtue has outlined the execution phase of its exploit recovery framework, shifting to “Plan B” after network validators declined to support a protocol upgrade (Plan A) that would have explicitly targeted the attacker’s wallet address.

The plan addresses the fallout from an August 28 oracle manipulation exploit that triggered 47 abnormal liquidations across 45 user accounts. With Plan A off the table, the team is moving forward with direct compensation and protocol reactivation steps.

Key Steps in the Plan B Remediation Strategy

Under Plan B, affected position holders will receive compensation directly in IOTA tokens based on their pre-liquidation net account values, amounting to an estimated 11.54 million IOTA across the protocol.

Related: Virtue Identifies $905,000 in Affected Collateral as IOTA Recovery Plan Takes Shape

The recovery roadmap includes several fixed milestones:

  • October 1 — Stability Pool Restoration: The protocol’s Stability Pool is being restored, returning 113,416.78 VUSD to non-attacker depositors.
  • October 19 — Protocol Relaunch & PSM Live: Virtue is set to relaunch core functionality alongside its Peg Stability Module (PSM).
  • USDT0 Minting Integration: Leveraging the launch of native USDT0 on the IOTA network, the PSM will allow users to mint VUSD at a 1:1 ratio against USDT0, strengthening the stablecoin’s peg mechanics.
  • Ongoing Judicial Pursuits: Asset recovery procedures are simultaneously proceeding through legal and judicial channels.

Security Guidance and Claim Warnings

Virtue emphasized that the Plan B distribution requires no active user interaction—eliminating the need for signatures, web portal claims, or wallet transfers.

Related: IOTA Validators Split Over Plan to Restore 23.2 Million IOTA in Virtue Positions

The protocol issued an explicit warning to its community regarding potential phishing scams: the team will never initiate direct messages, and any third party soliciting signatures or private keys under the guise of an “incident claim portal” is an impersonator. Official inquiries are directed solely to the protocol’s verified support email.

About The Author