Aperture Finance Loses $3.67M in Exploit, Hacker Deposits Funds Through Tornado Cash

TheNewsCryptoОпубліковано о 2026-02-05Востаннє оновлено о 2026-02-05

Анотація

Aperture Finance suffered a security breach on January 25, 2026, resulting in a loss of approximately $3.67 million. The exploit targeted specific versions of its smart contracts (V3 and V4), allowing the hacker to steal funds by exploiting vulnerabilities in contract approvals and function calls. The attacker subsequently deposited 1,242.7 ETH (worth around $2.4 million) into Tornado Cash, likely to obscure the transaction trail. In response, Aperture Finance disabled affected web app functions, released a security analysis, and urged users to revoke all related ERC-20 and ERC-721 approvals connected to the compromised addresses.

Aperture Finance suffered a security breach in specific versions of smart contracts, that results in a loss of around $3.67 million. On February 5, the Blockchain security firm PeckShieldAlert showed that the addresses believed to be the hackers had deposited 1,242.7 ETH into Tornado Cash, raising concerns.

Basically, the hack of Aperture Finance happened on January 25, 2026, as its security incident analysis reported that the exploit targeted smart contracts including V3 and V4. Aperture Finance is a DeFi platform that allows users to frequently shift their ERC-20 tokens or liquidity position NFTs, so that trades and strategies can be executed automatically.

However, in this case, the exploiter identified a problem in how the contract handled approvals and function calls. By which the hacker took advantage of these and stole the funds from the contracts.

Exploiter Moves $2.4M ETH to Tornado Cash

As this exploit has totaled nearly $3.67 million in value, the latest PeckShieldAlert data showed that the specific exploiter addresses have moved about 1,242 ETH, which is roughly $2.4 million into Tornado Cash, which raises concerns, as this step is likely intended to hide the record of the stolen crypto funds.

Soon after the exploit, Aperture Finance released the security incident analysis and announced that the affected web app functionalities had been stopped, with remediation and recovery messages.

Aperture Finance also attached the affected contracts list, as well as urged the users to revoke immediately both ERC-20 token approvals and ERC-721 liquidity position approvals that are connected to the risky addresses.

Highlighted Crypto News Today:

‌European Central Bank Likely to Keep Interest Rates Unchanged This Week

TagsAperture Finance

Пов'язані питання

QWhat was the total value lost in the Aperture Finance exploit?

AThe total value lost in the Aperture Finance exploit was approximately $3.67 million.

QWhich blockchain security firm reported on the hacker's activity with Tornado Cash?

AThe blockchain security firm PeckShieldAlert reported that the hacker deposited funds into Tornado Cash.

QOn what date did the Aperture Finance security breach occur?

AThe Aperture Finance security breach occurred on January 25, 2026.

QWhat specific type of smart contract versions were targeted in the exploit?

AThe exploit targeted smart contracts including V3 and V4 versions.

QWhat action did Aperture Finance urge its users to take immediately after the exploit?

AAperture Finance urged users to immediately revoke both ERC-20 token approvals and ERC-721 liquidity position approvals connected to the risky addresses.

Пов'язані матеріали

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru1 год тому

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru1 год тому

Торгівля

Спот
活动图片