Aperture Finance Loses $3.67M in Smart Contract Exploit as Stolen ETH Moves to Tornado Cash

Aperture Finance Loses $3.67M in Smart Contract Exploit as Stolen ETH Moves to Tornado Cash

N
News Editor 01
2026-07-23 01:50:15
Aperture Finance lost about $3.67 million after attackers abused flaws in its V3 and V4 smart contracts. Hack-linked wallets later sent 1,242 ETH to Tornado Cash, while users were told to revoke approvals immediately.
Aperture Financesmart contract exploitTornado CashDeFi securityon-chain security

Aperture Finance, a DeFi platform, lost about $3.67 million in a smart contract exploit. Blockchain security firm PeckShieldAlert said the attacker has already moved part of the stolen assets into ETH and sent roughly 1,242 ETH, valued in the source at about $2.4 million, to Tornado Cash.

V3 and V4 contracts were exploited through existing approvals

According to PeckShieldAlert, the attack took place on January 25, 2026 and involved weaknesses in Aperture Finance’s V3 and V4 smart contracts, along with token permissions users had granted earlier. In DeFi, users commonly approve contracts to manage ERC-20 tokens or liquidity position NFTs so trading and strategy functions can run automatically. In this case, the exploiter found a flaw in how those permissions and function calls were handled.

The attack did not rely on compromised wallets or stolen private keys. Instead, the exploiter used the contract’s own logic to trigger unauthorized transfers. Because many users had already approved the contracts, the attacker did not need fresh signatures to move assets tied to those token and liquidity position approvals.

Stolen funds were broken up and sent to Tornado Cash

After extracting about $3.67 million, the attacker converted a large portion into ETH and routed the funds through Tornado Cash to make tracing harder. The source says the transfers were split into multiple smaller transactions, including batches of 10 ETH and 100 ETH. That pattern is commonly seen in laundering flows after crypto thefts, as it makes on-chain tracking and recovery more difficult.

Users were told to revoke both token and NFT approvals

Following the exploit, Aperture Finance issued an emergency notice and published a list of affected contract addresses. Users were urged to immediately revoke approvals connected to those risky addresses, covering both ERC-20 token approvals and ERC-721 liquidity position approvals. If those approvals remain active after a contract has been compromised, user assets can stay exposed.

The incident details also make clear that private keys were not stolen in the breach. The risk came from abused smart contract permissions, leaving approved funds vulnerable even though users’ wallets themselves were not directly hacked.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.