TLDR Legacy Ribbon DOV vaults were drained of about $2.7 million on December 12. A December 6 oracle upgrade allowed users to set prices for new assets. The exploitTLDR Legacy Ribbon DOV vaults were drained of about $2.7 million on December 12. A December 6 oracle upgrade allowed users to set prices for new assets. The exploit

Aevo Shuts Ribbon Vaults After $2.7 Million Oracle Manipulation Exploit

2025/12/16 01:51

TLDR

  • Legacy Ribbon DOV vaults were drained of about $2.7 million on December 12.

  • A December 6 oracle upgrade allowed users to set prices for new assets.

  • The exploit affected Ethereum vaults but not Aevo’s Layer 2 exchange.

  • Aevo plans to decommission all Ribbon vaults and open a six month claim window.


Aevo confirmed that its legacy Ribbon Finance vaults lost about $2.7 million after a smart contract flaw. The issue followed an oracle upgrade that enabled price manipulation and targeted inactive DeFi options products.

The news is presented from the angle of an oracle upgrade vulnerability affecting dormant legacy DeFi infrastructure rather than active exchange operations.

Aevo Exploit linked to oracle upgrade

Security researchers reported that the exploit occurred on December 12, several days after an oracle upgrade. The upgrade was deployed on December 6 and affected price feeds for newly added assets.

Analysts said the change allowed any user to submit prices through proxy contracts. This allowed false expiry prices to be pushed into the shared oracle system. Assets involved included wstETH, AAVE, LINK, and WBTC.

Blockchain analyst Specter identified unusual outflows from Ribbon vault contracts. The funds were moved quickly after extraction. Most of the stolen value was held in ETH and USDC.

Another researcher, Liyi Zhou, explained the attack path in a public thread. Zhou wrote that a shared expiry timestamp was abused across multiple assets. This enabled coordinated price manipulation within the vault logic.

Scope of losses and fund movement

The total loss was estimated at about $2.7 million based on onchain data. Hundreds of ETH were removed alongside stablecoin balances. The attacker then spread funds across fifteen wallet addresses.

Several of those addresses received close to 100 ETH each. Researchers said this pattern suggested an attempt to reduce tracking risks. Centralized exchanges were alerted to monitor related wallets.

Anton Cheng of Monarch DeFi said the flaw was limited to Ribbon’s oracle setup. He stated that Opyn’s core protocol was not compromised. The weakness came from how Ribbon configured the upgrade.

Aevo also confirmed that its Layer 2 derivatives exchange was unaffected. Trading, deposits, and withdrawals on the exchange continued without interruption.

Response from Aevo and vault shutdown

Aevo announced that all Ribbon vaults were stopped following the incident. The team said the vaults would be fully decommissioned. No new activity will be allowed.

In a public statement, Aevo said,

The company proposed a plan for remaining vault users. Withdrawals would face a 19% reduction instead of the full 32% loss. Aevo said this approach favors active participants.

The DAO also said it would forfeit about $400,000 of its own vault positions. This step reduces the net loss to about $2.3 million. Aevo noted that no insurance was promised.

Claim process and next steps

Aevo set a six month claim window running from December 12 to June 12. Users can withdraw during this period under the proposed terms.

After the deadline, remaining assets will be liquidated by the DAO. Proceeds will be distributed to prior claimants. Payments may cover part or all of the remaining shortfall.

Aevo said many large accounts have been inactive for years. The team expects some deposits will remain unclaimed. These funds may help offset losses for active users.

A full post mortem is expected to be released. Aevo said it remains open to a whitehat resolution through its bounty program.

The post Aevo Shuts Ribbon Vaults After $2.7 Million Oracle Manipulation Exploit appeared first on CoinCentral.

Market Opportunity
Aevo Logo
Aevo Price(AEVO)
$0.03801
$0.03801$0.03801
-2.33%
USD
Aevo (AEVO) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
XRP Price Prediction: Can Ripple Rally Past $2 Before the End of 2025?

XRP Price Prediction: Can Ripple Rally Past $2 Before the End of 2025?

The post XRP Price Prediction: Can Ripple Rally Past $2 Before the End of 2025? appeared first on Coinpedia Fintech News The XRP price has come under enormous pressure
Share
CoinPedia2025/12/16 19:22
BlackRock boosts AI and US equity exposure in $185 billion models

BlackRock boosts AI and US equity exposure in $185 billion models

The post BlackRock boosts AI and US equity exposure in $185 billion models appeared on BitcoinEthereumNews.com. BlackRock is steering $185 billion worth of model portfolios deeper into US stocks and artificial intelligence. The decision came this week as the asset manager adjusted its entire model suite, increasing its equity allocation and dumping exposure to international developed markets. The firm now sits 2% overweight on stocks, after money moved between several of its biggest exchange-traded funds. This wasn’t a slow shuffle. Billions flowed across multiple ETFs on Tuesday as BlackRock executed the realignment. The iShares S&P 100 ETF (OEF) alone brought in $3.4 billion, the largest single-day haul in its history. The iShares Core S&P 500 ETF (IVV) collected $2.3 billion, while the iShares US Equity Factor Rotation Active ETF (DYNF) added nearly $2 billion. The rebalancing triggered swift inflows and outflows that realigned investor exposure on the back of performance data and macroeconomic outlooks. BlackRock raises equities on strong US earnings The model updates come as BlackRock backs the rally in American stocks, fueled by strong earnings and optimism around rate cuts. In an investment letter obtained by Bloomberg, the firm said US companies have delivered 11% earnings growth since the third quarter of 2024. Meanwhile, earnings across other developed markets barely touched 2%. That gap helped push the decision to drop international holdings in favor of American ones. Michael Gates, lead portfolio manager for BlackRock’s Target Allocation ETF model portfolio suite, said the US market is the only one showing consistency in sales growth, profit delivery, and revisions in analyst forecasts. “The US equity market continues to stand alone in terms of earnings delivery, sales growth and sustainable trends in analyst estimates and revisions,” Michael wrote. He added that non-US developed markets lagged far behind, especially when it came to sales. This week’s changes reflect that position. The move was made ahead of the Federal…
Share
BitcoinEthereumNews2025/09/18 01:44