The post Aevo-Ribbon Hack Exploits Oracle Upgrade, Drains $2.7M in Assets appeared on BitcoinEthereumNews.com. In Brief Aevo lost $2.7M due to manipulated expiryThe post Aevo-Ribbon Hack Exploits Oracle Upgrade, Drains $2.7M in Assets appeared on BitcoinEthereumNews.com. In Brief Aevo lost $2.7M due to manipulated expiry

Aevo-Ribbon Hack Exploits Oracle Upgrade, Drains $2.7M in Assets

2 min read

In Brief

  • Aevo lost $2.7M due to manipulated expiry prices after oracle system upgrade.
  • Attacker used fake options to exploit Ribbon’s MarginPool and drain ETH and USDC.
  • Funds were split across 15 wallets, some linked to treasury consolidation pools.


A sophisticated exploit drained $2.7 million from Aevo, formerly Ribbon Finance, targeting its outdated smart contract system. The attack occurred six days after an oracle upgrade changed the price-feed structure and decimal formatting for several tokens.

The attacker manipulated expiry prices by abusing the oracle’s proxy contract, submitting arbitrary values for assets like wstETH, AAVE, and LINK. They used these fake prices to settle option contracts in their favor, extracting hundreds of ETH and thousands in stablecoins.

Security analysts traced the attack to interactions with the oracle’s proxy admin contract, allowing unauthorized control over price updates. The malicious actor created poorly structured options using legitimate whitelisted tokens, avoiding detection during setup. These options were then used to trigger false settlements from Ribbon’s MarginPool.

Oracle changes created vulnerability; funds spread across multiple wallets

The issue began when Ribbon Finance updated its oracle system to support 18-decimal pricing for certain assets, excluding USDC. This inconsistency introduced a flaw that let attackers push fake expiry prices across all tokens with a shared timestamp.

Using oTokens based on stETH, collateralized with WETH, the attacker triggered settlements by forcing the system to recognize fake valuations. The smart contract then released assets to wallets controlled by the attacker, distributing the stolen funds across 15 addresses.

Blockchain investigators identified initial transfers to a wallet address that then routed funds into additional accounts. Many addresses held about 100 ETH each, and some have been linked to treasury consolidation pools. The total haul included around 900 ETH and large sums of USDC.

According to Web3 developers, the attack exploited Ribbon’s oracle upgrade but did not compromise the Opyn platform. The oToken creation process was followed correctly, but the lack of payout caps allowed unchecked asset drainage. Analysts confirmed Opyn’s core system remained secure throughout the incident.

DISCLAIMER: The information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Source: https://coincu.com/news/aevo-ribbon-hack-exploits-oracle-upgrade/

Market Opportunity
Aevo Logo
Aevo Price(AEVO)
$0.02885
$0.02885$0.02885
-0.55%
USD
Aevo (AEVO) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Strategy to initiate a bitcoin security program addressing quantum uncertainty

Strategy to initiate a bitcoin security program addressing quantum uncertainty

Markets Share Share this article
Copy linkX (Twitter)LinkedInFacebookEmail
Strategy to initiate a bitcoin security prog
Share
Coindesk2026/02/06 18:21
Strategic Shift Impacts Crypto Trading Landscape

Strategic Shift Impacts Crypto Trading Landscape

The post Strategic Shift Impacts Crypto Trading Landscape appeared on BitcoinEthereumNews.com. Bybit Delists MILK: Strategic Shift Impacts Crypto Trading Landscape
Share
BitcoinEthereumNews2026/02/06 18:01
SEC clears framework for fast-tracked crypto ETF listings

SEC clears framework for fast-tracked crypto ETF listings

The post SEC clears framework for fast-tracked crypto ETF listings appeared on BitcoinEthereumNews.com. The Securities and Exchange Commission has approved new generic listing standards for spot crypto exchange-traded funds, clearing the way for faster approvals. Summary SEC has greenlighted new generic listing standards for spot crypto ETFs. Rule change eliminates lengthy case-by-case approvals, aligning crypto ETFs with commodity funds. Grayscale’s Digital Large Cap Fund and Bitcoin ETF options also gain approval. The U.S. SEC has approved new generic listing standards that will allow exchanges to fast-track spot crypto ETFs, marking a pivotal shift in U.S. digital asset regulation. According to a Sept. 17 press release, the SEC voted to approve rule changes from Nasdaq, NYSE Arca, and Cboe BZX, enabling them to list and trade commodity-based trust shares, including those holding spot digital assets, without submitting individual proposals for each product. A streamlined path for crypto ETFs Under the new rules, an ETF can be listed without SEC sign-off if its underlying asset trades on a market with surveillance-sharing agreements, has active CFTC-regulated futures contracts for at least six months, or already represents at least 40% of an existing listed ETF. This brings crypto ETFs in line with traditional commodity-based funds under Rule 6c-11, eliminating a process that could take up to 240 days. SEC chair Paul Atkins said the move was designed to “maximize investor choice and foster innovation” while ensuring the U.S. remains the leading market for digital assets. Jamie Selway, director of the division of trading and markets, called the framework “a rational, rules-based approach” that balances access with investor protection. First products already approved Alongside the new standards, the SEC cleared the listing of the Grayscale Digital Large Cap Fund, which tracks spot assets based on the CoinDesk 5 Index. It also approved trading of options tied to the Cboe Bitcoin U.S. ETF Index and its mini version, with…
Share
BitcoinEthereumNews2025/09/18 14:04