TLDR Legacy Ribbon DOV vaults were drained of about $2.7 million on December 12. A December 6 oracle upgrade allowed users to set prices for new assets. The exploitTLDR Legacy Ribbon DOV vaults were drained of about $2.7 million on December 12. A December 6 oracle upgrade allowed users to set prices for new assets. The exploit

Aevo Shuts Ribbon Vaults After $2.7 Million Oracle Manipulation Exploit

2025/12/16 01:51
3 min read

TLDR

  • Legacy Ribbon DOV vaults were drained of about $2.7 million on December 12.

  • A December 6 oracle upgrade allowed users to set prices for new assets.

  • The exploit affected Ethereum vaults but not Aevo’s Layer 2 exchange.

  • Aevo plans to decommission all Ribbon vaults and open a six month claim window.


Aevo confirmed that its legacy Ribbon Finance vaults lost about $2.7 million after a smart contract flaw. The issue followed an oracle upgrade that enabled price manipulation and targeted inactive DeFi options products.

The news is presented from the angle of an oracle upgrade vulnerability affecting dormant legacy DeFi infrastructure rather than active exchange operations.

Aevo Exploit linked to oracle upgrade

Security researchers reported that the exploit occurred on December 12, several days after an oracle upgrade. The upgrade was deployed on December 6 and affected price feeds for newly added assets.

Analysts said the change allowed any user to submit prices through proxy contracts. This allowed false expiry prices to be pushed into the shared oracle system. Assets involved included wstETH, AAVE, LINK, and WBTC.

Blockchain analyst Specter identified unusual outflows from Ribbon vault contracts. The funds were moved quickly after extraction. Most of the stolen value was held in ETH and USDC.

Another researcher, Liyi Zhou, explained the attack path in a public thread. Zhou wrote that a shared expiry timestamp was abused across multiple assets. This enabled coordinated price manipulation within the vault logic.

Scope of losses and fund movement

The total loss was estimated at about $2.7 million based on onchain data. Hundreds of ETH were removed alongside stablecoin balances. The attacker then spread funds across fifteen wallet addresses.

Several of those addresses received close to 100 ETH each. Researchers said this pattern suggested an attempt to reduce tracking risks. Centralized exchanges were alerted to monitor related wallets.

Anton Cheng of Monarch DeFi said the flaw was limited to Ribbon’s oracle setup. He stated that Opyn’s core protocol was not compromised. The weakness came from how Ribbon configured the upgrade.

Aevo also confirmed that its Layer 2 derivatives exchange was unaffected. Trading, deposits, and withdrawals on the exchange continued without interruption.

Response from Aevo and vault shutdown

Aevo announced that all Ribbon vaults were stopped following the incident. The team said the vaults would be fully decommissioned. No new activity will be allowed.

In a public statement, Aevo said,

The company proposed a plan for remaining vault users. Withdrawals would face a 19% reduction instead of the full 32% loss. Aevo said this approach favors active participants.

The DAO also said it would forfeit about $400,000 of its own vault positions. This step reduces the net loss to about $2.3 million. Aevo noted that no insurance was promised.

Claim process and next steps

Aevo set a six month claim window running from December 12 to June 12. Users can withdraw during this period under the proposed terms.

After the deadline, remaining assets will be liquidated by the DAO. Proceeds will be distributed to prior claimants. Payments may cover part or all of the remaining shortfall.

Aevo said many large accounts have been inactive for years. The team expects some deposits will remain unclaimed. These funds may help offset losses for active users.

A full post mortem is expected to be released. Aevo said it remains open to a whitehat resolution through its bounty program.

The post Aevo Shuts Ribbon Vaults After $2.7 Million Oracle Manipulation Exploit appeared first on CoinCentral.

Market Opportunity
Aevo Logo
Aevo Price(AEVO)
$0.02972
$0.02972$0.02972
+1.60%
USD
Aevo (AEVO) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Galaxy Digital Authorizes $200M Share Buyback as Stock Rebounds

Galaxy Digital Authorizes $200M Share Buyback as Stock Rebounds

Galaxy Digital Holdings Ltd. announced this week that its board has authorized a $200 million share repurchase program for the company’s Class A common stock. Galaxy
Share
Coinstats2026/02/08 07:30
Kalshi debuts ecosystem hub with Solana and Base

Kalshi debuts ecosystem hub with Solana and Base

The post Kalshi debuts ecosystem hub with Solana and Base appeared on BitcoinEthereumNews.com. Kalshi, the US-regulated prediction market exchange, rolled out a new program on Wednesday called KalshiEco Hub. The initiative, developed in partnership with Solana and Coinbase-backed Base, is designed to attract builders, traders, and content creators to a growing ecosystem around prediction markets. By combining its regulatory footing with crypto-native infrastructure, Kalshi said it is aiming to become a bridge between traditional finance and onchain innovation. The hub offers grants, technical assistance, and marketing support to selected projects. Kalshi also announced that it will support native deposits of Solana’s SOL token and USDC stablecoin, making it easier for users already active in crypto to participate directly. Early collaborators include Kalshinomics, a dashboard for market analytics, and Verso, which is building professional-grade tools for market discovery and execution. Other partners, such as Caddy, are exploring ways to expand retail-facing trading experiences. Kalshi’s move to embrace blockchain partnerships comes at a time when prediction markets are drawing fresh attention for their ability to capture sentiment around elections, economic policy, and cultural events. Competitor Polymarket recently acquired QCEX — a derivatives exchange with a CFTC license — to pave its way back into US operations under regulatory compliance. At the same time, platforms like PredictIt continue to push for a clearer regulatory footing. The legal terrain remains complex, with some states issuing cease-and-desist orders over whether these event contracts count as gambling, not finance. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/kalshi-ecosystem-hub-solana-base
Share
BitcoinEthereumNews2025/09/18 04:40
First family moves on from Wall Street as Eric Trump backs crypto

First family moves on from Wall Street as Eric Trump backs crypto

Eric Trump says crypto could actually save the U.S. dollar. Not kill it. Not weaken it. On Tuesday, just hours after ringing the Nasdaq opening bell for American Bitcoin’s public debut, a company where he’s got over $500 million stashed, Eric told the Financial Times that crypto is “arguably” the reason the dollar might stay alive. “Mining bitcoin here, and being financially independent and running a kind of financial revolution out of the United States of America…I think it arguably saves the US dollar,” he said. The timing wasn’t random. Eric’s comments came while the dollar was getting dragged. This year, it’s been tanking… fast. The cause? President Donald Trump’s trade war and his endless public jabs at the Federal Reserve, which just slashed interest rates again. The Fed cut rates yesterday, for the first time this year, right after Donald’s latest round of pressure. It’s not helping. Investors are losing confidence in what’s supposed to be the safest currency on Earth. Eric says crypto is fun, family is done with Wall Street Eric isn’t just pushing crypto from the sidelines. His family has gone full throttle into the space. We’re talking a Truth Social Bitcoin ETF, a Bitcoin treasury tied to Trump Media, and two meme coins; $MELANIA and $TRUMP. Eric defended both coins, saying they were meant to be “fun,” and explained why people are buying in: “They want to bet on a coin, or they want to bet on a player. They want to bet on a celebrity, or they want to bet on a famous brand. Or they just love somebody to death, and they want to buy, you know, a kind of small piece of them, via digital currency.” And Eric doesn’t give Wall Street any credit. At all. He made it clear that everything they’ve built was done without the help of big-name banks. “It’s almost like the ultimate revenge against the big banks and modern finance,” he said. That jab came after the Trump Organization filed a lawsuit against Capital One, accusing the bank of closing their accounts in 2021 for political reasons — something the bank denies. But Eric wasn’t done. “You realise you just don’t need them. And frankly, you don’t miss them.” He added that he wasn’t just referring to Capital One, but “all” of Wall Street’s major lenders and their “top people.” Stablecoins, trillions, and the White House betting on crypto Stablecoins have traditional banks spooked. They think cash might flow out of the banking system if coins like Tether or Circle offer better returns. And that fear isn’t fake. It’s growing, especially after Congress passed the first major crypto law in July. Now the White House wants stablecoin issuers to buy up a fat slice of the Treasury’s debt. Why? Because these crypto firms make money on the interest from the bonds they hold. Last year, Eric co-founded World Liberty Financial Inc. (WLFI), a crypto company that runs a stablecoin called USD1, pegged to the U.S. dollar. That project has serious family backing. Donald held 15.75 billion WLFI tokens at the end of 2024, based on official filings. At Wednesday’s trading price, that holding was worth over $3 billion. When asked about the family’s financial gain from crypto, Eric downplayed it. “If my father cared about monetising his life, the last thing he would have done is run for president, where all we’ve done is un-monetise our life.” Your crypto news deserves attention - KEY Difference Wire puts you on 250+ top sites
Share
Coinstats2025/09/18 20:41