Aperture Finance Loses $3.67M in Exploit, Hacker Deposits Funds Through Tornado Cash

TheNewsCryptoPublished on 2026-02-05Last updated on 2026-02-05

Abstract

Aperture Finance suffered a security breach on January 25, 2026, resulting in a loss of approximately $3.67 million. The exploit targeted specific versions of its smart contracts (V3 and V4), allowing the hacker to steal funds by exploiting vulnerabilities in contract approvals and function calls. The attacker subsequently deposited 1,242.7 ETH (worth around $2.4 million) into Tornado Cash, likely to obscure the transaction trail. In response, Aperture Finance disabled affected web app functions, released a security analysis, and urged users to revoke all related ERC-20 and ERC-721 approvals connected to the compromised addresses.

Aperture Finance suffered a security breach in specific versions of smart contracts, that results in a loss of around $3.67 million. On February 5, the Blockchain security firm PeckShieldAlert showed that the addresses believed to be the hackers had deposited 1,242.7 ETH into Tornado Cash, raising concerns.

Basically, the hack of Aperture Finance happened on January 25, 2026, as its security incident analysis reported that the exploit targeted smart contracts including V3 and V4. Aperture Finance is a DeFi platform that allows users to frequently shift their ERC-20 tokens or liquidity position NFTs, so that trades and strategies can be executed automatically.

However, in this case, the exploiter identified a problem in how the contract handled approvals and function calls. By which the hacker took advantage of these and stole the funds from the contracts.

Exploiter Moves $2.4M ETH to Tornado Cash

As this exploit has totaled nearly $3.67 million in value, the latest PeckShieldAlert data showed that the specific exploiter addresses have moved about 1,242 ETH, which is roughly $2.4 million into Tornado Cash, which raises concerns, as this step is likely intended to hide the record of the stolen crypto funds.

Soon after the exploit, Aperture Finance released the security incident analysis and announced that the affected web app functionalities had been stopped, with remediation and recovery messages.

Aperture Finance also attached the affected contracts list, as well as urged the users to revoke immediately both ERC-20 token approvals and ERC-721 liquidity position approvals that are connected to the risky addresses.

Highlighted Crypto News Today:

‌European Central Bank Likely to Keep Interest Rates Unchanged This Week

TagsAperture Finance

Related Questions

QWhat was the total value lost in the Aperture Finance exploit?

AThe total value lost in the Aperture Finance exploit was approximately $3.67 million.

QWhich blockchain security firm reported on the hacker's activity with Tornado Cash?

AThe blockchain security firm PeckShieldAlert reported that the hacker deposited funds into Tornado Cash.

QOn what date did the Aperture Finance security breach occur?

AThe Aperture Finance security breach occurred on January 25, 2026.

QWhat specific type of smart contract versions were targeted in the exploit?

AThe exploit targeted smart contracts including V3 and V4 versions.

QWhat action did Aperture Finance urge its users to take immediately after the exploit?

AAperture Finance urged users to immediately revoke both ERC-20 token approvals and ERC-721 liquidity position approvals connected to the risky addresses.

Related Reads

Virtuals Collaborates with Ethereum Foundation to Release ERC-8183: A Trustless On-Chain Commerce Protocol

ERC-8183: Trustless On-Chain Commerce Protocol for AI Agents Virtuals Protocol and the Ethereum Foundation dAI team have jointly proposed ERC-8183, a standard for enabling trustless on-chain commercial interactions between AI agents. This is not merely a payment protocol but a comprehensive framework for task specification, escrow, delivery verification, and evaluator certification—forming the infrastructure for agentic commerce. The proposal addresses the core challenge of trust in AI-to-AI transactions, where traditional platforms or intermediaries are undesirable. It introduces a minimal "Job" primitive involving three parties: Client, Provider, and Evaluator. A Job progresses through states—Open, Funded, Submitted, and Terminal (Completed/Rejected/Expired)—ensuring programmable, neutral execution via smart contracts. Funds are held in escrow and released only upon evaluator approval of the work submitted. A key innovation is the modular "Hooks" system, allowing custom logic—such as bidding, reputation gating, or privacy preservation—to be added without modifying the core standard. ERC-8183 synergizes with ERC-8004 (Agent Identity and Reputation), creating a closed loop of discovery, transaction, and reputation accumulation. This standard aims to support an open, permissionless agent economy, enabling AI agents to transact at scale without relying on centralized platforms or traditional trust mechanisms. It is designed for extensibility and adaptability, anticipating diverse future use cases in decentralized AI commerce.

marsbit50m ago

Virtuals Collaborates with Ethereum Foundation to Release ERC-8183: A Trustless On-Chain Commerce Protocol

marsbit50m ago

Trading

Spot
Futures
活动图片