Ribbon Finance Hack

TOTAL LOST $351K
Low Phishing Attacks

What happened

A DNS attack was made on Ribbon Finance. During the attack one of the users lost 16.5 $WBTC.

A DNS attack was carried out on the Ribbon Finance project, during which 16.5 $WBTC was lost. The on-chain analysis revealed that the attack has common features with the DNS attack on Convex Finance and was made by the same hacker team. Hackers created a similar website with a malicious contract that required calling the approve() function.

Scammer address: https://etherscan.io/address/0xb7326148…5af9aa

Contract creator address: https://etherscan.io/address/0x47832f55…146fc6

Malicious contract address: https://etherscan.io/address/0x65a8ec2c…453b2f

Transferring 16.5 $WBTC from "victim" to scammer address transaction: https://etherscan.io/tx/0xd09057f1…510850

Case & protocol details

Classification Yield Aggregator
Protocol Type Exploit/Phishing
Affected asset / contract RBN
Official Website app.ribbon.finance/
Protocol Twitter/X @ribbonfinance

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.