Revert Lend Hack
What happened
On January 30, 2026, Revert's newly deployed Aerodrome Lend vault on Base lost about 50,101.74 USDC after an attacker withdrew liquidity from a collateralized LP NFT while leaving the vault with an NFT that no longer represented the expected collateral value. No third-party user funds were in the affected pool.
The staking and position-management layer lacked an invariant preventing a collateralized LP position with active debt from being modified in a way that reduced its collateral value outside the vault's control.
Case & protocol details
Attack Timeline
The attacker used flash-loaned capital to mint an Aerodrome Slipstream LP NFT, deposited it as collateral, borrowed USDC, and staked the position through the vault's management flow. A GaugeManager execution path could temporarily unstake and modify a position even while it backed active debt. The attacker used that path to withdraw liquidity, repaid the flash loan, and retained the borrowed USDC.
Revert paused the Aerodrome Lend vault shortly after verification; its postmortem says the affected USDC was team capital and no user deposits were in the pool.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Revert: Aerodrome Lend Vault Incident Post-Mortem paragraph.com
- transaction Transaction basescan.org
- transaction Transaction basescan.org
- analysis Website reference paragraph.com
- analysis Website reference x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.