Aperture LM Hack
What happened
On January 25, 2026, Aperture's helper-module vulnerability was exploited across Ethereum, Base, and Arbitrum for approximately $3.67 million.
The helper module insufficiently constrained user-controlled low-level-call inputs. That allowed arbitrary transferFrom parameters to be executed against assets that users had approved to the affected contracts.
Case & protocol details
Attack Timeline
Attackers supplied malicious helper-module inputs that reached a low-level call and invoked approved-token transferFrom operations from victim wallets to attacker-controlled addresses.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- transaction Transaction etherscan.io
- analysis BlockSec: January 25–February 1, 2026 incident roundup blocksec.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.