Guavy AI Editorial TeamSentiment: -4Clout: 70

Aevo's Ribbon Vaults Drained $2.7M by Exploiters

The DeFi options vaults from Ribbon Finance, now rebranded as Aevo, were drained of approximately $2.7 million on Dec. 12 due to a vulnerability in their oracle configuration.

The exploit targeted smart contracts that remained active on Ethereum despite the 2023 rebranding and affected only the Opyn/Ribbon oracle stack.

Crypt analysts traced the issue to an Oracle upgrade on Dec. 6, which inadvertently allowed any user to set prices for newly added assets.

Anton Cheng of Monarch DeFi confirmed that the upgrade let anyone set prices for new assets, and Liyi Zhou published a detailed analysis explaining how the attacker manipulated the oracle stack.