Aave Protocol Hack

TOTAL LOST $1.2M
Medium Phishing Attacks

What happened

A user's Aave Protocol assets were stolen using phishing attack, which resulted in a loss of 1,201,576 $USD.

A user approved trading for four different tokens of Aave Protocol, such as $aArbWETH, $aFanWETH, $aArbWBTC and $aFanUSDC, possible via phishing attack. The attacker took the assets and then swapped them into 1,201,576 $USDC using four smart contract with unverified source code, and than all selfdestructed. The funds were transferred through Celer Bridge.

Attacker addresses:

https://arbiscan.io/address/0x053a85c5…8408d1

https://arbiscan.io/address/0x0a009741…f00012

Malicious transaction:

https://arbiscan.io/tx/0x3c79b996…4a2467

Approval transaction:

https://arbiscan.io/tx/0x4d8ecb31…e54ed1

Case & protocol details

Classification Borrowing and Lending
Protocol Type Exploit/Phishing
Official Website www.ravenprotocol.com/

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.