Aperture Finance hack — January 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | January 25, 2026 |
| Target type | Other |
| Loss | $3,670,000Published estimates range $3,670,000 to $3,670,000Price at time of incident |
| Method | Access control flawArbitrary external call in the protocol's closed-source position-manager contract. A swap routine accepted a caller-supplied target address and calldata without restricting them to approved DEX routers or function selectors, so the attacker aimed the low-level call at token contracts and invoked transferFrom() against standing ERC-20 and Uniswap V3 position-NFT approvals. BlockSec found the contract validated approval spenders but not the execution target. |
| Chains | Ethereum, Arbitrum, Base |
| Outcome | Unresolved |
What happened
On 25 January 2026 attackers drained assets from Aperture Finance, a DeFi liquidity-management protocol that automates Uniswap V3 positions across Ethereum, Arbitrum and Base. The loss did not involve stolen keys. A swap routine inside the protocol's closed-source position-manager contract accepted a target address and calldata supplied by the caller without restricting them to approved DEX routers or function selectors. BlockSec, which reconstructed the attack from decompiled bytecode, found that the contract validated approval spenders but never validated the address it actually called. The attacker pointed the low-level call at token contracts and invoked transferFrom() against the standing ERC-20 and Uniswap V3 position-NFT approvals users had granted the protocol. SolidityScan reached the same conclusion in a separate bytecode analysis, classifying it as an arbitrary-call vulnerability caused by insufficient input validation, under the OWASP SC Top 10 category of unchecked external calls. Aperture halted core front-end functions to stop new approvals, published a list of affected contract addresses, and urged users to revoke both ERC-20 token approvals and ERC-721 liquidity-position approvals tied to the risky addresses. The figures are contested at the level of the combined incident rather than Aperture's own share. PeckShield first put the Aperture loss at $3.67 million, and BlockSec's later breakdown gives the same figure while attributing a further roughly $13.41 million to SwapNet, a separate protocol hit by the same class of bug the same day; that pairing is the origin of the widely repeated $17 million headline. SolidityScan also cites $3.67 million. AMLBot's on-chain tracing describes combined losses across both protocols of more than $13.5 million and publishes no per-protocol split. AMLBot separately identifies a second, distinct wave of activity beginning hours after the initial exploit, a copycat attacker holding about $3.2 million, and links that wallet cluster to the Li.Fi Protocol / Jumper Exchange attacker — but does not state which of the two victim protocols those funds came from. AMLBot places about 540 ETH at the primary attacker address on Base and notes roughly $3 million in USDC left untouched.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0xe3E73f1E6acE2B27891D41369919e8F57129e8eA
Sources
- BlockSecSecondary · retrieved 2026-08-01
- SolidityScanSecondary · retrieved 2026-08-01
- Coinpedia (reporting PeckShield's figure)Secondary · retrieved 2026-08-01
- Gate News (quoting Aperture Finance's X statement)Secondary · retrieved 2026-08-01
- AMLBotSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Aperture Finance hack — January 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/aperture-financehttps://itokenly.com/hacks/aperture-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.