The post Aevo-Ribbon Hack Exploits Oracle Upgrade, Drains $2.7M in Assets appeared on BitcoinEthereumNews.com. In Brief Aevo lost $2.7M due to manipulated expiryThe post Aevo-Ribbon Hack Exploits Oracle Upgrade, Drains $2.7M in Assets appeared on BitcoinEthereumNews.com. In Brief Aevo lost $2.7M due to manipulated expiry

Aevo-Ribbon Hack Exploits Oracle Upgrade, Drains $2.7M in Assets

In Brief

  • Aevo lost $2.7M due to manipulated expiry prices after oracle system upgrade.
  • Attacker used fake options to exploit Ribbon’s MarginPool and drain ETH and USDC.
  • Funds were split across 15 wallets, some linked to treasury consolidation pools.


A sophisticated exploit drained $2.7 million from Aevo, formerly Ribbon Finance, targeting its outdated smart contract system. The attack occurred six days after an oracle upgrade changed the price-feed structure and decimal formatting for several tokens.

The attacker manipulated expiry prices by abusing the oracle’s proxy contract, submitting arbitrary values for assets like wstETH, AAVE, and LINK. They used these fake prices to settle option contracts in their favor, extracting hundreds of ETH and thousands in stablecoins.

Security analysts traced the attack to interactions with the oracle’s proxy admin contract, allowing unauthorized control over price updates. The malicious actor created poorly structured options using legitimate whitelisted tokens, avoiding detection during setup. These options were then used to trigger false settlements from Ribbon’s MarginPool.

Oracle changes created vulnerability; funds spread across multiple wallets

The issue began when Ribbon Finance updated its oracle system to support 18-decimal pricing for certain assets, excluding USDC. This inconsistency introduced a flaw that let attackers push fake expiry prices across all tokens with a shared timestamp.

Using oTokens based on stETH, collateralized with WETH, the attacker triggered settlements by forcing the system to recognize fake valuations. The smart contract then released assets to wallets controlled by the attacker, distributing the stolen funds across 15 addresses.

Blockchain investigators identified initial transfers to a wallet address that then routed funds into additional accounts. Many addresses held about 100 ETH each, and some have been linked to treasury consolidation pools. The total haul included around 900 ETH and large sums of USDC.

According to Web3 developers, the attack exploited Ribbon’s oracle upgrade but did not compromise the Opyn platform. The oToken creation process was followed correctly, but the lack of payout caps allowed unchecked asset drainage. Analysts confirmed Opyn’s core system remained secure throughout the incident.

DISCLAIMER: The information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Source: https://coincu.com/news/aevo-ribbon-hack-exploits-oracle-upgrade/

Piyasa Fırsatı
Aevo Logosu
Aevo Fiyatı(AEVO)
$0.03771
$0.03771$0.03771
-1.28%
USD
Aevo (AEVO) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Exodus Partners with MoonPay to Launch Fully Reserved USD-Backed Stablecoin on M0 Infrastructure

Exodus Partners with MoonPay to Launch Fully Reserved USD-Backed Stablecoin on M0 Infrastructure

Exodus, known for its user-friendly self-custody wallet supporting multiple blockchains, will integrate the new stablecoin into its product suite, providing its user base with seamless access to the digital dollar. MoonPay, which has established itself as a leading fiat on-ramp and off-ramp service, brings its payment rails and regulatory relationships to the partnership. M0, a newer entrant focused specifically on stablecoin infrastructure, provides the underlying technology stack.
Paylaş
MEXC NEWS2025/12/17 12:35
Aave Founder Unveils 2026 Master Plan: V4 Upgrade, Institutional RWA Platform Horizon, and New Application

Aave Founder Unveils 2026 Master Plan: V4 Upgrade, Institutional RWA Platform Horizon, and New Application

Aave founder Stani Kulechov recently unveiled the decentralized lending protocol's 2026 strategic plan, revealing an ambitious development blueprint. This master plan centers on three core pillars: the next-generation Aave V4 protocol upgrade, Horizon—a real-world asset (RWA) platform built specifically for institutional investors—and a new Aave application designed to lower barriers for users. In presenting this roadmap, Kulechov demonstrated unwavering confidence in Aave's future, concluding with a succinct and powerful declaration: "Aave will win."
Paylaş
MEXC NEWS2025/12/17 12:25
OpenAI in Talks to Raise $10B+ from Amazon, Plans to Adopt Amazon's AI Chips

OpenAI in Talks to Raise $10B+ from Amazon, Plans to Adopt Amazon's AI Chips

According to The Information, OpenAI is in discussions with Amazon regarding an investment exceeding $10 billion and plans to adopt Amazon's artificial intelligence chips. If confirmed, this would mark a momentous strategic alliance between two heavyweight players in the AI space. For OpenAI, this potential funding would provide ample capital for its continuously expanding AI infrastructure development. The computational costs required to train and run large language models are extraordinarily high, and rapid user growth has further intensified demand for computing resources. Additional capital injection would help OpenAI maintain its technological edge in the ongoing AI arms race.
Paylaş
MEXC NEWS2025/12/17 12:28