Medium Smart contract exploit Source: DeFiLlama Hacks

Aperture LM — Token Approval Abuse

Aperture LM was exploited for approximately $3.67 million across Ethereum, Base, Arbitrum, and BSC due to an arbitrary-call vulnerability in its contracts. Attackers abused existing user token and Uniswap V3 LP NFT approvals to drain funds. The team paused affected features and urged users to revoke approvals.

Estimated loss
$3,670,000
Protocols
Aperture LM
Chains
Ethereum, Base, BSC, Arbitrum
Confidence
High
First seen
25 Jan 2026, 00:00 UTC

Read the original report ↗ (opens in a new tab)