The post Aevo-Ribbon Hack Exploits Oracle Upgrade, Drains $2.7M in Assets appeared on BitcoinEthereumNews.com. In Brief Aevo lost $2.7M due to manipulated expiryThe post Aevo-Ribbon Hack Exploits Oracle Upgrade, Drains $2.7M in Assets appeared on BitcoinEthereumNews.com. In Brief Aevo lost $2.7M due to manipulated expiry

Aevo-Ribbon Hack Exploits Oracle Upgrade, Drains $2.7M in Assets

In Brief

  • Aevo lost $2.7M due to manipulated expiry prices after oracle system upgrade.
  • Attacker used fake options to exploit Ribbon’s MarginPool and drain ETH and USDC.
  • Funds were split across 15 wallets, some linked to treasury consolidation pools.


A sophisticated exploit drained $2.7 million from Aevo, formerly Ribbon Finance, targeting its outdated smart contract system. The attack occurred six days after an oracle upgrade changed the price-feed structure and decimal formatting for several tokens.

The attacker manipulated expiry prices by abusing the oracle’s proxy contract, submitting arbitrary values for assets like wstETH, AAVE, and LINK. They used these fake prices to settle option contracts in their favor, extracting hundreds of ETH and thousands in stablecoins.

Security analysts traced the attack to interactions with the oracle’s proxy admin contract, allowing unauthorized control over price updates. The malicious actor created poorly structured options using legitimate whitelisted tokens, avoiding detection during setup. These options were then used to trigger false settlements from Ribbon’s MarginPool.

Oracle changes created vulnerability; funds spread across multiple wallets

The issue began when Ribbon Finance updated its oracle system to support 18-decimal pricing for certain assets, excluding USDC. This inconsistency introduced a flaw that let attackers push fake expiry prices across all tokens with a shared timestamp.

Using oTokens based on stETH, collateralized with WETH, the attacker triggered settlements by forcing the system to recognize fake valuations. The smart contract then released assets to wallets controlled by the attacker, distributing the stolen funds across 15 addresses.

Blockchain investigators identified initial transfers to a wallet address that then routed funds into additional accounts. Many addresses held about 100 ETH each, and some have been linked to treasury consolidation pools. The total haul included around 900 ETH and large sums of USDC.

According to Web3 developers, the attack exploited Ribbon’s oracle upgrade but did not compromise the Opyn platform. The oToken creation process was followed correctly, but the lack of payout caps allowed unchecked asset drainage. Analysts confirmed Opyn’s core system remained secure throughout the incident.

DISCLAIMER: The information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Source: https://coincu.com/news/aevo-ribbon-hack-exploits-oracle-upgrade/

Piyasa Fırsatı
Aevo Logosu
Aevo Fiyatı(AEVO)
$0.03773
$0.03773$0.03773
-1.23%
USD
Aevo (AEVO) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Solana Faces Massive DDoS Attack Without Performance Issues

Solana Faces Massive DDoS Attack Without Performance Issues

Solana successfully countered a major DDoS attack without affecting users. The network maintained transaction confirmation times around 450 milliseconds. Continue
Paylaş
Coinstats2025/12/17 13:08
A ‘Star Wars’ Actor Rewrites The Entire New Trilogy They Starred In

A ‘Star Wars’ Actor Rewrites The Entire New Trilogy They Starred In

The post A ‘Star Wars’ Actor Rewrites The Entire New Trilogy They Starred In appeared on BitcoinEthereumNews.com. It feels like we don’t hear all that much from actor John Boyega that much, outside of when he’s talking about Star Wars as of late. And in a recent Popverse interview, he went so far as to rework the entire trilogy, in terms of what he’d do differently, as he’s been vocal about what he believed went wrong with the original. Here’s what he said: “It would be mad. First of all, we’re not getting rid of Han Solo, Luke Skywalker, all these people. We’re not doing that. The first thing we’re going to do is fulfill their story, fulfill their legacy. We’re going to make a good moment of handing on the baton.” “Luke Skywalker wouldn’t be disappearing on a rock … Hell no. Standing there and he’s, like, a projector? I would want to give those characters way more way more” By the end of the trilogy, all three major Star Wars leads are dead. Han Solo killed by his son, Kylo Ren. Luke Skywalker fading into the ether after force projecting himself to face Kylo Ren. Leia had to be written off due to the tragic death of Carrie Fisher during the production of the trilogy. So Boyega would halt at least the first two deaths, as it did come off as strange that “passing the baton” was mainly killing all the big characters. He continues: “Our new characters will not be overpowered in these movies. They won’t just grab stuff and know what to do with it… No. You’ve got to struggle like every other character in this franchise.” This is likely a reference to both Rey and himself. Rey was frequently criticized as a “Mary Sue,” possessing immense power and skill in everything from flying to fighting to the force despite growing up as…
Paylaş
BitcoinEthereumNews2025/09/25 02:37
Discover Mono Protocol: The $2M-Backed Project Built to Simplify Development, Launch Faster, and Monetize Every Transaction

Discover Mono Protocol: The $2M-Backed Project Built to Simplify Development, Launch Faster, and Monetize Every Transaction

Developing in Web3 has often meant navigating fragmented systems, high transaction costs, and complex cross-chain infrastructure. Mono Protocol introduces a new approach that brings clarity and efficiency to this landscape. It focuses on three powerful outcomes: simplify development, launch faster, and monetize every transaction.  By unifying balances, streamlining execution, and integrating monetization at the core, […]
Paylaş
Cryptopolitan2025/09/18 21:28