A $2.7M oracle hit is one problem for Aevo; a 19% payback cap on a 32% vault loss is another for anyone still underwriting Ribbon risk. The post Aevo’s Ribbon VaultA $2.7M oracle hit is one problem for Aevo; a 19% payback cap on a 32% vault loss is another for anyone still underwriting Ribbon risk. The post Aevo’s Ribbon Vault

Aevo’s Ribbon Vault Exploit Spurs Backlash Over 19% Payout Plan

2025/12/15 15:53

Aevo, the derivatives venue built by the former Ribbon Finance team, confirmed a $2.7 million loss from its legacy Ribbon DOV vaults after an oracle-related smart contract upgrade on December 12.

Shortly after, the project team relayed that Aevo will permanently disable all Ribbon vaults and run a capped recovery process for affected users. It explained that the old Ribbon DOV vault was hacked on December 12 due to smart contract vulnerabilities in a recent update, leading to a $2.7 million loss.

As a consequence, all Ribbon vaults were paused and should soon be permanently disabled, with a six‑month claims window through June 12, 2026. The post adds that the DAO will liquidate remaining assets to compensate users “up to 19% of the missing amount or the remaining balance,” whichever is lower.

How the Ribbon vault hack actually happened

Blockchain investigators reconstructed the attack path using the exploit contract at 0x3c212A044760DE5a529B3Ba59363ddeCcc2210bE and at least 15 recipient addresses first flagged by on‑chain analyst Specter on X. Specter wrote that “the old contract of @ribbonfinance has been drained for a total of $2.7M,” listing theft addresses that received drained [NC] and stablecoins.

Security write‑ups from multiple venues agree that the attacker abused the oracle proxy admin to submit arbitrary expiry prices for wstETH, AAVE, [NC] , and other underlyings, then settled oToken positions against Ribbon’s MarginPool to pull assets from the vaults.

Post‑mortems point to a decimal‑mismatch bug introduced six days earlier, when Ribbon updated the oracle pricer to 18‑decimal feeds for stETH, PAXG, LINK, and AAVE while keeping USDC at eight decimals. Web3 security researcher Weilin highlighted that the configuration allowed forged expiry prices at a shared timestamp across assets, which the settlement pipeline then treated as valid for prominent short oToken positions. Funds now sit spread across the original 15 addresses and several consolidation wallets, with no public recovery negotiation from the attacker.

Aevo price reacts with a drop

The market has already marked Aevo down. AEVO trades at about $0.041 per token today, with a 7-day drop of 7% and a market cap of $37.7 million on a circulating supply of 915.8 million. That price sits 98.9% below the March 28, 2024, all‑time high of $3.86.

Aevo price in 7 days | Source: CoinMarketCap

Aevo price in 7 days | Source: CoinMarketCap

Implied protocol value now hovers close to the on‑chain TVL of around $28.2 million, which compresses the margin for error when the DAO socializes a 32% vault loss yet only promises up to 19% reimbursement.

Community backlash over Ribbon recovery plan

Community reaction to the recovery terms of 19% has turned hostile across social channels and secondary reporting.

Commenters argue that early Ribbon depositors, who left assets in deprecated DOV vaults based on prior assurances, now eat an 80%+ haircut. At the same time, Aevo continues to run its main derivatives exchange and L2 stack unaffected.

Users also report that some threads have been deleted, and that commenting on Aevo’s posts is now limited to verified accounts and those previously mentioned by Aevo. The company directs users toward the formal claims process rather than open debate.

From an institutional angle, the exploit itself looks like a textbook oracle‑config failure. Still, the response mirrors prior stress episodes around Mango, Euler, and others, where the technical fix landed faster than the social one.

A desk that routes size through Aevo now has to price not just smart contract risk, but governance and social‑layer risk in any vault product that carries the Ribbon legacy brand, since the DAO has set a precedent that losses in older vault lines can clear at a fraction of face value even while the core trading venue and token remain live.

next

The post Aevo’s Ribbon Vault Exploit Spurs Backlash Over 19% Payout Plan appeared first on Coinspeaker.

Piyasa Fırsatı
Aevo Logosu
Aevo Fiyatı(AEVO)
$0.038
$0.038$0.038
-2.36%
USD
Aevo (AEVO) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Paylaş
BitcoinEthereumNews2025/09/18 00:09
XRP ETF’s bereiken belangrijke mijlpaal: $1 miljard aan netto instroom

XRP ETF’s bereiken belangrijke mijlpaal: $1 miljard aan netto instroom

De markt voor crypto-exchange-traded funds (ETF’s) heeft opnieuw een belangrijke mijlpaal bereikt. XRP ETF’s hebben gezamenlijk meer dan 1 miljard dollar aan netto
Paylaş
Coinstats2025/12/16 21:01
XSGD And XUSD Launch On Solana’s Blazing Network In 2025

XSGD And XUSD Launch On Solana’s Blazing Network In 2025

The post XSGD And XUSD Launch On Solana’s Blazing Network In 2025 appeared on BitcoinEthereumNews.com. StraitsX Stablecoins Unleash Power: XSGD And XUSD Launch
Paylaş
BitcoinEthereumNews2025/12/16 20:59