Ribbon Finance Hack
What happened
A DNS attack was made on Ribbon Finance. During the attack one of the users lost 16.5 $WBTC.
A DNS attack was carried out on the Ribbon Finance project, during which 16.5 $WBTC was lost. The on-chain analysis revealed that the attack has common features with the DNS attack on Convex Finance and was made by the same hacker team. Hackers created a similar website with a malicious contract that required calling the approve() function.
Scammer address: https://etherscan.io/address/0xb7326148…5af9aa
Contract creator address: https://etherscan.io/address/0x47832f55…146fc6
Malicious contract address: https://etherscan.io/address/0x65a8ec2c…453b2f
Transferring 16.5 $WBTC from "victim" to scammer address transaction: https://etherscan.io/tx/0xd09057f1…510850
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report blog.bybit.com
- report Report lockmeta.com
- report Report tokeninsight.com
- analysis Web Archive web.archive.org
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.