Aperture Finance Loses $3.67M in Exploit, Hacker Deposits Funds Through Tornado Cash

TheNewsCrypto2026-02-05 tarihinde yayınlandı2026-02-05 tarihinde güncellendi

Özet

Aperture Finance suffered a security breach on January 25, 2026, resulting in a loss of approximately $3.67 million. The exploit targeted specific versions of its smart contracts (V3 and V4), allowing the hacker to steal funds by exploiting vulnerabilities in contract approvals and function calls. The attacker subsequently deposited 1,242.7 ETH (worth around $2.4 million) into Tornado Cash, likely to obscure the transaction trail. In response, Aperture Finance disabled affected web app functions, released a security analysis, and urged users to revoke all related ERC-20 and ERC-721 approvals connected to the compromised addresses.

Aperture Finance suffered a security breach in specific versions of smart contracts, that results in a loss of around $3.67 million. On February 5, the Blockchain security firm PeckShieldAlert showed that the addresses believed to be the hackers had deposited 1,242.7 ETH into Tornado Cash, raising concerns.

Basically, the hack of Aperture Finance happened on January 25, 2026, as its security incident analysis reported that the exploit targeted smart contracts including V3 and V4. Aperture Finance is a DeFi platform that allows users to frequently shift their ERC-20 tokens or liquidity position NFTs, so that trades and strategies can be executed automatically.

However, in this case, the exploiter identified a problem in how the contract handled approvals and function calls. By which the hacker took advantage of these and stole the funds from the contracts.

Exploiter Moves $2.4M ETH to Tornado Cash

As this exploit has totaled nearly $3.67 million in value, the latest PeckShieldAlert data showed that the specific exploiter addresses have moved about 1,242 ETH, which is roughly $2.4 million into Tornado Cash, which raises concerns, as this step is likely intended to hide the record of the stolen crypto funds.

Soon after the exploit, Aperture Finance released the security incident analysis and announced that the affected web app functionalities had been stopped, with remediation and recovery messages.

Aperture Finance also attached the affected contracts list, as well as urged the users to revoke immediately both ERC-20 token approvals and ERC-721 liquidity position approvals that are connected to the risky addresses.

Highlighted Crypto News Today:

‌European Central Bank Likely to Keep Interest Rates Unchanged This Week

TagsAperture Finance

İlgili Sorular

QWhat was the total value lost in the Aperture Finance exploit?

AThe total value lost in the Aperture Finance exploit was approximately $3.67 million.

QWhich blockchain security firm reported on the hacker's activity with Tornado Cash?

AThe blockchain security firm PeckShieldAlert reported that the hacker deposited funds into Tornado Cash.

QOn what date did the Aperture Finance security breach occur?

AThe Aperture Finance security breach occurred on January 25, 2026.

QWhat specific type of smart contract versions were targeted in the exploit?

AThe exploit targeted smart contracts including V3 and V4 versions.

QWhat action did Aperture Finance urge its users to take immediately after the exploit?

AAperture Finance urged users to immediately revoke both ERC-20 token approvals and ERC-721 liquidity position approvals connected to the risky addresses.

İlgili Okumalar

From Payment to Deployment: Stripe Bets on the AI Agent Economy

From Payments to Deployment: Stripe Bets on the AI Agent Economy Stripe is redefining economic infrastructure for the AI era, shifting its focus from serving primarily human users and software companies to enabling machine agents as active economic participants. The core thesis is that AI agents are evolving from tools into independent buyers and builders on the internet, necessitating a complete overhaul of traditional payment, billing, and deployment models. To empower agents as **buyers**, Stripe, in collaboration with Tempo, developed the Machine Payments Protocol. This protocol allows businesses to programmatically accept payments from agents without human intervention, using machine-readable payment instructions. Furthermore, Stripe's consumer wallet, Link, is being adapted to let users securely authorize agents to spend on their behalf. To empower agents as **builders**, Stripe Projects aims to simplify the deployment process. It allows developers and their agents to register, manage, and integrate the services needed to deploy applications directly from the command line, making "vibe-deploying" as seamless as "vibe-coding." This agent-driven economy, where products have real, variable costs (like AI tokens), disrupts traditional SaaS models. **Token-based monetization** is becoming central, requiring usage-based billing that charges for actual resource consumption, as seen with companies like Lovable and ElevenLabs. However, this model introduces new challenges like **token theft**, where fraudsters exploit services and vanish before billing. Stripe Radar helps combat this by assessing new accounts and predicting abuse risks. A critical innovation to balance customer experience and financial risk is **streaming payments**. By combining Metronome (for real-time usage tracking) with Tempo (for low-cost, high-frequency stablecoin payments), Stripe enables AI companies to collect fees *as tokens are consumed*. This eliminates the trade-off between imposing hard usage caps and risking unpaid invoices. In summary, Stripe's vision for AI economic infrastructure now encompasses providing a commercial framework for agents, wallets for agents, deployment tools for agents, token-based billing, fraud prevention for token abuse, and streaming payment capabilities. As AI transforms both commerce and software creation, Stripe is building the foundational infrastructure to support it.

marsbit1 saat önce

From Payment to Deployment: Stripe Bets on the AI Agent Economy

marsbit1 saat önce

İşlemler

Spot
Futures
活动图片