Aevo confirmed on December 13, 2025 that legacy Ribbon Finance DeFi Options Vaults had been exploited, producing an estimated loss of approximately $2.7 million. The project attributed the incident to a vulnerability associated with a smart-contract update and said it was working with centralized exchanges and security partners to trace and flag the funds.

The attack itself occurred on December 12. Aevo’s confirmation on December 13 was the first attributable project record establishing the estimated loss, the affected product and the company’s initial description of the cause. The figure was a project estimate, not an independently audited accounting of every affected asset.

Ethereum records corroborate that unusual contract activity occurred on December 12. One transaction associated by Etherscan with the Ribbon Finance exploiter succeeded at 07:52:11 UTC and created several contracts before transferring multiple token types. That transaction is primary on-chain evidence of activity within the attack sequence, but it does not independently prove the complete $2.7 million valuation.

A legacy product remained a live liability

The affected contracts belonged to Ribbon’s DeFi Options Vault product line. These vaults pooled depositor assets and used structured options strategies, including covered calls and put selling, to generate returns. Their operation depended on contract logic and price information used to create and settle options positions.

Ribbon’s governance community had proposed folding Ribbon into Aevo’s broader structured-products business in July 2023. That proposal distinguished the Ethereum-based vault products from Aevo’s newer options and perpetual-futures exchange operating on a custom layer-two network. The historical separation became material during the December 2025 incident.

Aevo said on December 13 that its principal platform, users and stakers were unaffected and that the exchange continued operating. That was a contemporaneous company claim about the incident’s scope. The available event-day evidence supported a distinction between the legacy vault contracts and the principal Aevo exchange, but it was not a comprehensive independent audit of every Aevo system.

Why the confirmation mattered

The incident demonstrated that software described as legacy can continue to carry active financial exposure. A protocol may change its brand, governance structure or principal product without eliminating risks in older contracts that still custody assets or interact with shared infrastructure.

It also highlighted the consequences of modifying oracle-related components. Options settlement relies on accurate asset prices, correct decimal handling and tightly controlled administrative privileges. A fault in any of those layers can create payouts that the surrounding contracts execute exactly as programmed, even when the resulting transfer is economically invalid.

The project’s approximately $2.7 million estimate was significant for affected depositors but did not imply that Aevo’s layer-two network had failed or that the entire protocol had lost the same percentage of its assets. No event-day evidence reviewed for this reconstruction established a market-wide impact, a verified identity for the attacker or a completed recovery.

What remained uncertain on December 13

Aevo’s initial statement identified a vulnerability in a smart-contract update but did not publish a complete technical postmortem on December 13. Independent researchers examining the transactions focused on the Ribbon oracle configuration and the ability to introduce manipulated expiry prices. Those analyses were technically informative, but they were not equivalent to a final project report.

The surviving record also did not establish the final depositor shortfall, the recoverable amount or whether exchanges could freeze any proceeds. Asset valuations can change while funds are distributed across addresses, making a dollar estimate sensitive to both the valuation timestamp and the set of transfers included.

Later technical context

A Halborn analysis published on December 15 described a combination of access-control weaknesses and inconsistent decimal precision in the updated oracle system. That later assessment helps explain the transaction sequence but was not fully available when Aevo issued its December 13 confirmation. It therefore clarifies rather than replaces the narrower event-day record.

Primary sourceAevo statement confirming the legacy Ribbon vault exploit

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.