Revert Lend Hack

TOTAL LOST $50K
Low Access Control Attacks base

What happened

On January 30, 2026, Revert's newly deployed Aerodrome Lend vault on Base lost about 50,101.74 USDC after an attacker withdrew liquidity from a collateralized LP NFT while leaving the vault with an NFT that no longer represented the expected collateral value. No third-party user funds were in the affected pool.

Technical Root Cause

The staking and position-management layer lacked an invariant preventing a collateralized LP position with active debt from being modified in a way that reduced its collateral value outside the vault's control.

Case & protocol details

Classification Protocol Logic / Collateral Invariant Failure
Protocol Type Lending
Smart Contract Language Solidity
Official Website revert.finance/
Protocol Twitter/X @revertfinance

Attack Timeline

The attacker used flash-loaned capital to mint an Aerodrome Slipstream LP NFT, deposited it as collateral, borrowed USDC, and staked the position through the vault's management flow. A GaugeManager execution path could temporarily unstake and modify a position even while it backed active debt. The attacker used that path to withdraw liquidity, repaid the flash loan, and retained the borrowed USDC.

Revert paused the Aerodrome Lend vault shortly after verification; its postmortem says the affected USDC was team capital and no user deposits were in the pool.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.