Ribbon Finance DeFi Option Vaults (Aevo) hack — December 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | December 13, 2025 |
| Target type | Other |
| Loss | $2,700,000Price at time of incident |
| Method | Oracle or price manipulationAn upgrade to the Opyn/Ribbon oracle stack deployed on 6 December 2025 left the price-setting path for newly added assets open to any caller. A malicious contract submitted arbitrary expiry prices through the price-feed proxies for wstETH, AAVE, LINK and WBTC, then minted mispriced oTokens and redeemed them against the option vaults. |
| Chains | Ethereum |
| Outcome | Project shut down |
What happened
The legacy Ribbon Finance DeFi Option Vaults, still running on Ethereum after the protocol rebranded to Aevo in 2023, were drained of about $2.7 million on 12 December 2025. The outflows were noticed publicly the following day.
The cause was a change to the Opyn/Ribbon oracle stack deployed on 6 December 2025. The upgrade left the price-setting path for newly added assets open to any caller, so an attacker could submit arbitrary settlement prices through the price-feed proxies rather than having to move a market. Researcher Liyi Zhou described a malicious contract abusing those proxies to set fraudulent expiry prices for wstETH, AAVE, LINK and WBTC; the attacker minted mispriced oTokens and redeemed them against the vaults, extracting ETH, wstETH, USDC and WBTC. On-chain analyst Specter first flagged the outflows and developer Anton Cheng published a technical breakdown. Cryptopolitan reported the proceeds were spread across fifteen addresses, some later consolidated.
Aevo said the legacy Ribbon vaults had been exploited following a vulnerability in a smart contract update, then disabled and permanently decommissioned all of them. The loss represented roughly 32 per cent of vault assets. Rather than pass that through in full, Aevo proposed reducing withdrawable position values by 19 per cent, with the DAO forfeiting about $400,000 of its own vault positions to absorb the difference, leaving a net loss of roughly $2.3 million. A six-month claim window was opened from 12 December 2025 to 12 June 2026, after which remaining assets are to be liquidated and distributed. Aevo said the vaults had never carried a deposit insurance promise. Aevo's layer-2 derivatives exchange was unaffected.
Sources
- The BlockSecondary · retrieved 2026-08-01
- CryptopolitanSecondary · retrieved 2026-08-01
- CoinCentralSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Ribbon Finance DeFi Option Vaults (Aevo) hack — December 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/ribbon-dov-vaultshttps://itokenly.com/hacks/ribbon-dov-vaultsPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.