News View Non-AMP

Aperture Finance Hit by $3.67M Smart Contract Exploit, Funds Laundered via Tornado Cash

Published by
Rizwan Ansari and Qadir AK

DeFi platform Aperture Finance has suffered a major security breach, losing about $3.67 million in a smart contract exploit. Blockchain security firm PeckShieldAlert shows the hacker is actively moving stolen funds through Tornado Cash, a privacy-mixing service. 

The activity has raised new concerns about fund recovery and how the actual hack happened.

How The Aperture Finance Exploit Happened

According to PeckShieldAlert, the Aperture Finance hack happened on January 25, 2026, due to a weakness in its V3 and V4 smart contracts, combined with existing user token approvals.

In DeFi platforms, users often permit contracts to move their ERC-20 tokens or liquidity position NFTs so trades and strategies can run automatically. But in this case, the exploiter found a flaw in how the contract handled those permissions and function calls.

Instead of breaking wallets or stealing private keys, the attacker used the contract’s own logic to trigger unauthorized asset transfers.

Because many users had already granted approvals, the attacker could move funds without needing new signatures. This allowed them to drain assets tied to approved tokens and liquidity positions.

Funds Moved to Tornado Cash After Hack

And all this led to the extraction of $3.67 million in value, the attacker converted a large share into ETH, and sent about 1,242 ETH to Tornado Cash to hide the trail.

Attackers often use mixing services like Tornado Cash to hide the origin of stolen crypto and make tracking more difficult. The funds were sent in multiple small transactions, including batches of 10 ETH and 100 ETH, a common method used to avoid attention.

Users Asked to Revoke Token and NFT Approvals

Following the exploit, the Aperture Finance team released an emergency notice and shared a list of affected contract addresses. And also warned users to urgently revoke both ERC-20 token approvals and ERC-721 liquidity position approvals tied to the risky addresses. 

Wallet approvals allow smart contracts to move user funds, and if left active, they can be abused after a contract is compromised.

FAQs

How did the Aperture Finance hack happen?

Hackers exploited a weakness in the platform’s smart contracts, using existing user token approvals to move assets without stealing private keys.

What should Aperture Finance users do now?

Users should immediately revoke all token and liquidity position approvals linked to the affected contract addresses to prevent further losses.

Why are stolen crypto funds sent to Tornado Cash?

Services like Tornado Cash obscure transaction trails, making it difficult to track and recover stolen cryptocurrency after a hack.

Was my private key stolen in the Aperture breach?

No. The exploit abused smart contract permissions; your private keys remain secure, but your approved funds were at risk.

Rizwan Ansari and Qadir AK

Rizwan is an experienced Crypto journalist with almost half a decade of experience covering everything related to the growing crypto industry — from price analysis to blockchain disruption. During this period, he’s authored more than 3,000 news articles for Coinpedia News.

Published by
Rizwan Ansari and Qadir AK
Tags: Hack

Trust with CoinPedia:

CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.

Investment Disclaimer:

All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.

Recent Posts

XRP Price Crashes 10%, But This Isn’t Panic Selling Here’s What On-Chain Data Shows

XRP price saw a sharp downside pressure during the latest session, dropping close to 10%…

February 5, 2026

Vitalik Buterin Warns Ethereum L2 Projects: Stop Copying, Start Innovating

Ethereum co-founder Vitalik Buterin has taken aim at the current state of Layer 2 projects…

February 5, 2026

Hyperliquid and MYX Finance Prices Recover Amid Market Correction—Is Bullish Momentum Building?

Bitcoin remains under pressure, trading close to $72,000, despite a recovery from $70,034, while Ethereum…

February 5, 2026

Crypto Liquidations Top $700M as Bitcoin, Ethereum and Altcoins Extend Selloff

The broader crypto market came under heavy pressure today as a sharp wave of crypto…

February 5, 2026

Why Is the Crypto Market Crashing Today?

The crypto market is going through a sharp downturn. The total value of all cryptocurrencies…

February 5, 2026

Was ZKsync Price Manipulated on Upbit? 15 Wallets Make $18.7M in Hours

South Korea's Financial Supervisory Service (FSS) has opened an investigation into ZKsync (ZK) after the…

February 5, 2026