Aevo's Ribbon Vaults Suffer $2.7M Loss Due to Oracle Exploit
DeFi Exploit Overview: Ribbon Finance's legacy DeFi options vaults were exploited for approximately $2.7 million due to a vulnerability in their oracle configuration following a Dec. 6 upgrade, allowing unauthorized price setting for new assets.
Impact and Response: Aevo has halted all Ribbon vaults and proposed a 19% reduction on position values for withdrawals, despite vaults experiencing around 32% losses, with plans to liquidate remaining assets after a six-month claim window.
Security Analysis: Blockchain analyst Specter and security researcher Liyi Zhou highlighted how the attacker manipulated the oracle stack to push arbitrary expiry prices for various assets, leading to significant theft.
Ongoing Risks in DeFi: The incident underscores the persistent risk of oracle manipulation in DeFi, as evidenced by a similar exploit earlier this year that resulted in a $717,000 loss for Venus Protocol on ZKsync.
About the author








