A $2.7M oracle hit is one problem for Aevo; a 19% payback cap on a 32% vault loss is another for anyone still underwriting Ribbon risk. The post Aevo’s Ribbon VaultA $2.7M oracle hit is one problem for Aevo; a 19% payback cap on a 32% vault loss is another for anyone still underwriting Ribbon risk. The post Aevo’s Ribbon Vault

Aevo’s Ribbon Vault Exploit Spurs Backlash Over 19% Payout Plan

Aevo, the derivatives venue built by the former Ribbon Finance team, confirmed a $2.7 million loss from its legacy Ribbon DOV vaults after an oracle-related smart contract upgrade on December 12.

Shortly after, the project team relayed that Aevo will permanently disable all Ribbon vaults and run a capped recovery process for affected users. It explained that the old Ribbon DOV vault was hacked on December 12 due to smart contract vulnerabilities in a recent update, leading to a $2.7 million loss.

As a consequence, all Ribbon vaults were paused and should soon be permanently disabled, with a six‑month claims window through June 12, 2026. The post adds that the DAO will liquidate remaining assets to compensate users “up to 19% of the missing amount or the remaining balance,” whichever is lower.

How the Ribbon vault hack actually happened

Blockchain investigators reconstructed the attack path using the exploit contract at 0x3c212A044760DE5a529B3Ba59363ddeCcc2210bE and at least 15 recipient addresses first flagged by on‑chain analyst Specter on X. Specter wrote that “the old contract of @ribbonfinance has been drained for a total of $2.7M,” listing theft addresses that received drained [NC] and stablecoins.

Security write‑ups from multiple venues agree that the attacker abused the oracle proxy admin to submit arbitrary expiry prices for wstETH, AAVE, [NC] , and other underlyings, then settled oToken positions against Ribbon’s MarginPool to pull assets from the vaults.

Post‑mortems point to a decimal‑mismatch bug introduced six days earlier, when Ribbon updated the oracle pricer to 18‑decimal feeds for stETH, PAXG, LINK, and AAVE while keeping USDC at eight decimals. Web3 security researcher Weilin highlighted that the configuration allowed forged expiry prices at a shared timestamp across assets, which the settlement pipeline then treated as valid for prominent short oToken positions. Funds now sit spread across the original 15 addresses and several consolidation wallets, with no public recovery negotiation from the attacker.

Aevo price reacts with a drop

The market has already marked Aevo down. AEVO trades at about $0.041 per token today, with a 7-day drop of 7% and a market cap of $37.7 million on a circulating supply of 915.8 million. That price sits 98.9% below the March 28, 2024, all‑time high of $3.86.

Aevo price in 7 days | Source: CoinMarketCap

Aevo price in 7 days | Source: CoinMarketCap

Implied protocol value now hovers close to the on‑chain TVL of around $28.2 million, which compresses the margin for error when the DAO socializes a 32% vault loss yet only promises up to 19% reimbursement.

Community backlash over Ribbon recovery plan

Community reaction to the recovery terms of 19% has turned hostile across social channels and secondary reporting.

Commenters argue that early Ribbon depositors, who left assets in deprecated DOV vaults based on prior assurances, now eat an 80%+ haircut. At the same time, Aevo continues to run its main derivatives exchange and L2 stack unaffected.

Users also report that some threads have been deleted, and that commenting on Aevo’s posts is now limited to verified accounts and those previously mentioned by Aevo. The company directs users toward the formal claims process rather than open debate.

From an institutional angle, the exploit itself looks like a textbook oracle‑config failure. Still, the response mirrors prior stress episodes around Mango, Euler, and others, where the technical fix landed faster than the social one.

A desk that routes size through Aevo now has to price not just smart contract risk, but governance and social‑layer risk in any vault product that carries the Ribbon legacy brand, since the DAO has set a precedent that losses in older vault lines can clear at a fraction of face value even while the core trading venue and token remain live.

next

The post Aevo’s Ribbon Vault Exploit Spurs Backlash Over 19% Payout Plan appeared first on Coinspeaker.

Market Opportunity
Aevo Logo
Aevo Price(AEVO)
$0.03653
$0.03653$0.03653
-1.77%
USD
Aevo (AEVO) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Fed Q1 2026 Outlook and Its Potential Impact on Crypto Markets

Fed Q1 2026 Outlook and Its Potential Impact on Crypto Markets

The post Fed Q1 2026 Outlook and Its Potential Impact on Crypto Markets appeared on BitcoinEthereumNews.com. Key takeaways: Fed pauses could pressure crypto, but
Share
BitcoinEthereumNews2025/12/26 07:41
Taiko Makes Chainlink Data Streams Its Official Oracle

Taiko Makes Chainlink Data Streams Its Official Oracle

The post Taiko Makes Chainlink Data Streams Its Official Oracle appeared on BitcoinEthereumNews.com. Key Notes Taiko has officially integrated Chainlink Data Streams for its Layer 2 network. The integration provides developers with high-speed market data to build advanced DeFi applications. The move aims to improve security and attract institutional adoption by using Chainlink’s established infrastructure. Taiko, an Ethereum-based ETH $4 514 24h volatility: 0.4% Market cap: $545.57 B Vol. 24h: $28.23 B Layer 2 rollup, has announced the integration of Chainlink LINK $23.26 24h volatility: 1.7% Market cap: $15.75 B Vol. 24h: $787.15 M Data Streams. The development comes as the underlying Ethereum network continues to see significant on-chain activity, including large sales from ETH whales. The partnership establishes Chainlink as the official oracle infrastructure for the network. It is designed to provide developers on the Taiko platform with reliable and high-speed market data, essential for building a wide range of decentralized finance (DeFi) applications, from complex derivatives platforms to more niche projects involving unique token governance models. According to the project’s official announcement on Sept. 17, the integration enables the creation of more advanced on-chain products that require high-quality, tamper-proof data to function securely. Taiko operates as a “based rollup,” which means it leverages Ethereum validators for transaction sequencing for strong decentralization. Boosting DeFi and Institutional Interest Oracles are fundamental services in the blockchain industry. They act as secure bridges that feed external, off-chain information to on-chain smart contracts. DeFi protocols, in particular, rely on oracles for accurate, real-time price feeds. Taiko leadership stated that using Chainlink’s infrastructure aligns with its goals. The team hopes the partnership will help attract institutional crypto investment and support the development of real-world applications, a goal that aligns with Chainlink’s broader mission to bring global data on-chain. Integrating real-world economic information is part of a broader industry trend. Just last week, Chainlink partnered with the Sei…
Share
BitcoinEthereumNews2025/09/18 03:34
Choosing an AI for Coding: A Practical Guide

Choosing an AI for Coding: A Practical Guide

There are now so many AI tools for coding that it can be confusing to know which one to pick. Some act as simple helpers (Assistant), while others can do the work
Share
Hackernoon2025/12/26 02:00