MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Aevo’s legacy Ribbon DOV vaults exploited for $2.7 million following oracle upgrade
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$68,950.00-0.80%
  • ethereumEthereum(ETH)$2,004.23-3.39%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.513.54%
  • binancecoinBNB(BNB)$618.48-1.94%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$87.31-0.29%
  • tronTRON(TRX)$0.280345-0.79%
  • dogecoinDogecoin(DOGE)$0.1072283.74%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.33%
Smart Contracts

Aevo’s legacy Ribbon DOV vaults exploited for $2.7 million following oracle upgrade

Last updated: December 15, 2025 10:45 am
Published: 2 months ago
Share

Aevo’s legacy Ribbon Finance smart contracts were exploited for approximately $2.7 million on Dec. 12, after an oracle infrastructure upgrade inadvertently enabled price manipulation, according to blockchain security researchers.

The attack targeted Ribbon’s DeFi Options Vaults (DOV), which are structured products that once held over $300 million in total value locked during DeFi’s peak. The vaults remained active on Ethereum despite Ribbon Finance’s 2023 rebrand and transition into derivatives exchange Aevo. The exploit did not affect Aevo’s primary Layer 2 exchange, the team said.

Blockchain analyst Specter first flagged suspicious outflows on X, identifying the exploit contract address and initial theft wallets. The attacker extracted hundreds of ETH and significant USDC holdings before distributing the proceeds to 15 separate addresses, many holding approximately 100 ETH each.

Security researcher Liyi Zhou published a detailed thread on X explaining that the attacker manipulated the Opyn/Ribbon oracle stack by abusing price-feed proxies. The exploit pushed arbitrary expiry prices for wstETH, AAVE, LINK, and WBTC into the shared oracle at a common expiry timestamp.

Anton Cheng of Monarch DeFi noted that exploit was made possible by a Dec. 6 upgrade to the oracle code that “let anyone set prices for new assets.” Cheng confirmed that the underlying Opyn protocol was not compromised, as the vulnerability was specific to Ribbon’s oracle configuration.

Aevo will decommission all Ribbon vaults

In a statement on X, Aevo said all Ribbon vaults have been stopped and will be decommissioned immediately. While the vaults suffered approximately 32% in losses, the team proposed that withdrawals be subject to only a 19% reduction on position value at the time of the hack.

Aevo said it can offer the smaller haircut for two reasons: the DAO will forfeit its own vault positions (roughly $400,000 in various assets) to partially offset the theft, reducing net losses to $2.3 million. Second, the team said accounts with the largest deposits have gone dormant over the past two to four years and likely won’t withdraw at all.

“We’re proposing to prioritize active users by granting them a smaller reduction upfront,” the team wrote. “Given the expected dormancy rate, there’s a strong chance that users who withdraw during the claim window will ultimately be made whole after the final distribution.”

The claim window will run six months from Dec. 12 to June 12. After that date, the DAO will liquidate remaining assets and distribute them to users who previously withdrew, compensating up to the missing 19% or as much as remains available. The team noted the DAO “never promised or offered insurance on deposits.”

Oracle manipulation remains a persistent DeFi attack vector. Earlier this year, Venus Protocol on ZKsync lost $717,000 to a similar exploit, The Block previously reported.

Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

Read more on TradingView

This news is powered by TradingView TradingView

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

XRP Achieves Trump-Era Breakthrough: Price Could Surge 735-Fold To $1,470 Following ETF Launch
$MOBU Surges as the Next 100X Crypto to Buy with Top Picks
Cardano Price Prediction: ADA Stalls 70% Below 2021 Highs as Little Pepe (LILPEPE) Sees Huge Token-Holder Spike in a Week
Hongqiao Forum discusses financial backing for global trade
Winklevoss Twins Launch $100M Zcash DAT as Privacy Narrative Surges – FinanceFeeds

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Investing in planetary health would deliver higher GDP, fewer deaths, less poverty: report
Next Article Synthetix Network to Launch Perpetual DEX on Ethereum Mainnet on December 17
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d