A sophisticated attack on Aevo-rebrand Ribbon Finance drained $2.7 million from its old contract and moved to fifteen separate wallet addresses, some of which haveA sophisticated attack on Aevo-rebrand Ribbon Finance drained $2.7 million from its old contract and moved to fifteen separate wallet addresses, some of which have

Ribbon Finance, formerly Aevo, loses $2.7 million in DeFi hack

A sophisticated attack on Aevo-rebrand Ribbon Finance drained $2.7 million from its old contract and moved to fifteen separate wallet addresses, some of which have already been consolidated into larger accounts. 

According to several blockchain investigators on social platform X, the attack occurred just six days after the platform upgraded its oracle infrastructure and option creation procedures. They used a smart contract prompt to extract hundreds of Ethereum tokens and other digital assets.

In a thread explaining the exploit, Web3 security analyst Liyi Zhou said a malicious contract manipulated the Opyn/Ribbon oracle stack by abusing price-feed proxies, and pushed arbitrary expiry prices for wstETH, AAVE, LINK, and WBTC into the shared oracle at a common expiry timestamp. 

“The attacker placed large short oToken positions against Ribbon Finance’s MarginPool, which used these forged expiry prices in its settlement pipeline and transferred out hundreds of WETH and wstETH, thousands of USDC, and several WBTC to theft addresses through redeem and redeemTo transactions,” Zhou explained.

Ribbon Finance’s oracle price upgrade had weaknesses

Six days before the attack, Ribbon Finance’s team updated the oracle pricer to support 18 decimals for stETH, PAXG, LINK, and AAVE. However, other assets, including USDC, were still at eight decimals, and according to Zhou, the discrepancy in decimal precision contributed to the vulnerability that was exploited on Friday.

According to a pseudonymous developer going by the username Weilin on X, the creation of oTokens themselves was not illegal because every underlying token must be whitelisted before it’s used as collateral or a strike asset, a procedure the attacker followed to the letter.

The malicious activity began with the creation of poorly structured option products, where one product consisted of a stETH call option with a 3,800 USDC strike, collateralized with WETH, set to expire on December 12. The attacker then created several oTokens for these options, which were later exploited to drain the protocol.

The attack involved repeated interactions with the proxy admin contract at 0x9D7b…8ae6B76. Some functions, like transferOwnership and setImplementation, were used to manipulate the price-feed proxies through delegate calls. The hacker invoked an implementation for the oracle to set asset expiry prices at the same timestamp to cause ExpiryPriceUpdated events that confirmed the fraudulent valuations.

The manipulated prices made the system recognize stETH as being far above the strike price and burned 225 oTokens, yielding 22.468662541163160869 WETH. In total, the hacker extracted approximately 900 ETH through this method.

Web3 security firm Spectre spotted the initial transfers to a wallet address at 0x354ad…9a355e, but from there, the money was distributed to 14 more accounts, with many holding around 100.1 ETH each. Some of the stolen funds have already entered what blockchain Zhou referred to as “TC” or treasury consolidation pools.

DeFi lending protocol builder: Opyn dApp was not compromised 

According to Monarch DeFi developer Anton Cheng, Coinbase-backed decentralized application Opyn was not compromised as rumored in chatter on Crypto Twitter.

Cheng explained that the Ribbon Finance hack was facilitated by an upgraded oracle code that inadvertently allowed any user to set prices for newly added assets. He denoted that the attack began with a preparatory transaction to “set the stage” by generating poorly structured oTokens with legitimate collateral and strike assets. He continued to say that the fake tokens allowed the hacker to pick well-known underlyings like AAVE to avoid drawing attention and getting flagged. 

The hacker then set up three “subaccounts,” each depositing minimal collateral to mint all three options. All subaccounts were marked as type 0, meaning they were fully collateralized, but the absence of a maximum payout limit for each account or oToken helped the perpetrator drain assets without any restrictions.

Under Opyn’s Gamma systems, the underlying asset must match the collateral for call options and the strike for puts to keep sellers fully collateralized. If an oracle is compromised, only sellers for that specific product are meant to suffer.

Yet in this case, the combination of new oToken creation and the manipulated oracle were enough to bypass these protections.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Piyasa Fırsatı
FINANCE Logosu
FINANCE Fiyatı(FINANCE)
$0.0002188
$0.0002188$0.0002188
-1.12%
USD
FINANCE (FINANCE) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

The post Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now? appeared on BitcoinEthereumNews.com. On the lookout for a Sector – Tech fund? Starting with Putnam Global Technology A (PGTAX – Free Report) should not be a possibility at this time. PGTAX possesses a Zacks Mutual Fund Rank of 4 (Sell), which is based on various forecasting factors like size, cost, and past performance. Objective We note that PGTAX is a Sector – Tech option, and this area is loaded with many options. Found in a wide number of industries such as semiconductors, software, internet, and networking, tech companies are everywhere. Thus, Sector – Tech mutual funds that invest in technology let investors own a stake in a notoriously volatile sector, but with a much more diversified approach. History of fund/manager Putnam Funds is based in Canton, MA, and is the manager of PGTAX. The Putnam Global Technology A made its debut in January of 2009 and PGTAX has managed to accumulate roughly $650.01 million in assets, as of the most recently available information. The fund is currently managed by Di Yao who has been in charge of the fund since December of 2012. Performance Obviously, what investors are looking for in these funds is strong performance relative to their peers. PGTAX has a 5-year annualized total return of 14.46%, and is in the middle third among its category peers. But if you are looking for a shorter time frame, it is also worth looking at its 3-year annualized total return of 27.02%, which places it in the middle third during this time-frame. It is important to note that the product’s returns may not reflect all its expenses. Any fees not reflected would lower the returns. Total returns do not reflect the fund’s [%] sale charge. If sales charges were included, total returns would have been lower. When looking at a fund’s performance, it…
Paylaş
BitcoinEthereumNews2025/09/18 04:05
Crypto Casino Luck.io Pays Influencers Up to $500K Monthly – But Why?

Crypto Casino Luck.io Pays Influencers Up to $500K Monthly – But Why?

Crypto casino Luck.io is reportedly paying influencers six figures a month to promote its services, a June 18 X post from popular crypto trader Jordan Fish, aka Cobie, shows. Crypto Influencers Reportedly Earning Six Figures Monthly According to a screenshot of messages between Cobie and an unidentified source embedded in the Wednesday post, the anonymous messenger confirmed that the crypto company pays influencers “around” $500,000 per month to promote the casino. They’re paying extremely well (6 fig per month) pic.twitter.com/AKRVKU9vp4 — Cobie (@cobie) June 18, 2025 However, not everyone was as convinced of the number’s accuracy. “That’s only for Faze Banks probably,” one user replied. “Other influencers are getting $20-40k per month. So, same as other online crypto casinos.” Cobie pushed back on the user’s claims by identifying the messenger as “a crypto person,” going on to state that he knew of “4 other crypto people” earning “above 200k” from Luck.io. Drake’s Massive Stake.com Deal Cobie’s post comes amid growing speculation over celebrity and influencer collaborations with crypto casinos globally. Aubrey Graham, better known as Toronto-based rapper Drake, is reported to make nearly $100 million every year from his partnership with cryptocurrency casino Stake.com. As part of his deal with the Curaçao-based digital casino, the “Nokia” rapper occasionally hosts live-stream gambling sessions for his more than 140 million Instagram followers. Founded by entrepreneurs Ed Craven and Bijan Therani in 2017, the organization allegedly raked in $2.6 billion in 2022. Stake.com has even solidified key partnerships with Alfa Romeo’s F1 team and Liverpool-based Everton Football Club. However, concerns remain over crypto casinos’ legality as a whole , given their massive accessibility and reach online. Earlier this year, Stake was slapped with litigation out of Illinois for supposedly running an illegal online casino stateside while causing “severe harm to vulnerable populations.” “Stake floods social media platforms with slick ads, influencer videos, and flashy visuals, making its games seem safe, fun, and harmless,” the lawsuit claims. “By masking its real-money gambling platform as just another “social casino,” Stake creates exactly the kind of dangerous environment that Illinois gambling laws were designed to stop.”
Paylaş
CryptoNews2025/06/19 04:53
U.S. Banks Near Stablecoin Issuance Under FDIC Genius Act Plan

U.S. Banks Near Stablecoin Issuance Under FDIC Genius Act Plan

The post U.S. Banks Near Stablecoin Issuance Under FDIC Genius Act Plan appeared on BitcoinEthereumNews.com. U.S. banks could soon begin applying to issue payment
Paylaş
BitcoinEthereumNews2025/12/17 02:55