Ribbon Hack

Reported loss $2.7M
Ethereum
Private Key Compromised

What happened

On December 12, 2025, legacy Ethereum Ribbon DeFi Options Vaults were exploited for about $2.7 million after an oracle upgrade enabled arbitrary price setting for newly added assets. The incident affected the legacy vaults that remained active after Ribbon rebranded to Aevo, not Aevo's primary Layer 2 exchange. Aevo stopped and announced the decommissioning of all Ribbon vaults.

How it happened

  1. A December 6 oracle upgrade left the Oracle contract's setAssetPricer() access control open, allowing arbitrary asset-price setting.
  2. The attacker initially configured a legitimate-looking oracle and opened a call-option position.
  3. At the option exercise date, the attacker replaced it with a malicious oracle that reported an inflated price and exercised the position for profit.
  4. The attacker distributed proceeds, primarily ETH and stablecoins, to 15 addresses; Aevo stopped the legacy Ribbon vaults and announced decommissioning.

Protocol details

Classification Protocol Logic / Access Control
Protocol Type Options Vault
Implementation language Solidity
Protocol links Website @ribbonfinance

Security review history

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.