Aperture LM Hack

TOTAL LOST $3.7M
Medium Access Control Attacks ethereum base arbitrum

What happened

On January 25, 2026, Aperture's helper-module vulnerability was exploited across Ethereum, Base, and Arbitrum for approximately $3.67 million.

Technical Root Cause

The helper module insufficiently constrained user-controlled low-level-call inputs. That allowed arbitrary transferFrom parameters to be executed against assets that users had approved to the affected contracts.

Case & protocol details

Classification Protocol Logic / Access Control
Protocol Type Liquidity manager
Smart Contract Language Solidity
Official Website aperture.finance
Protocol Twitter/X @ApertureFinance

Attack Timeline

Attackers supplied malicious helper-module inputs that reached a low-level call and invoked approved-token transferFrom operations from victim wallets to attacker-controlled addresses.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.