Revoke.cash logo

Aperture Finance Hack

Check if your address is affected.

25 Jan 2026
$3.7M stolen
Ethereum Logo
BNB Chain Logo
Base Logo
Arbitrum Logo
Optimism Logo
Avalanche Logo
Polygon Logo
Unichain Logo
Scroll Logo
Manta Pacific Logo

Aperture Finance is an AI-powered intents platform that helps users manage their liquidity positions on decentralized exchanges like Uniswap, PancakeSwap, Aerodrome and Velodrome. To mint a position, add liquidity or reinvest in one step, users approved Aperture's contracts to move their tokens and their LP position NFTs. On 25 January 2026, attackers found that one of these contracts did not properly check the instructions it was given. That let them use it to pull approved tokens and LP positions straight out of users' wallets.

Losses came to about $3.7M across several chains, including Ethereum, Arbitrum and Base. The attacker swapped much of the stolen funds for ETH and sent around 1,242 ETH through the Tornado Cash mixer to hide the trail. Aperture shut down the core features of its web app to stop new approvals and told users to revoke. It said it was working with forensic security firms and law enforcement to trace the funds, and that it would try to negotiate their return.

According to Aperture, only users who approved the contracts behind its instant liquidity features (minting, adding liquidity and reinvesting) are at risk. Its automation strategies, such as auto-rebalancing, auto-compounding and limit orders, run on separate contracts and were not affected. If you ever used Aperture's instant liquidity features on any chain, check your approvals and revoke any that point to the listed contracts, including approvals for LP position NFTs. Revoking protects what is still in your wallet, but it does not recover assets that were already taken.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits