GoPlus: Suspected "project party management address being controlled by hackers" led to the attack on Ribbon Finance

Dec 15, 2025 16:38:45

Share to

GoPlus Chinese community analyzes the principle of the attack on the decentralized options protocol Ribbon Finance in a social media post.

The attacker upgraded the price oracle contract to a malicious implementation contract through the address 0x657CDE, and then set the expiration time of four tokens: stETH, Aave, PAXG, and LINK to December 12, 2025, 16:00:00 (UTC+8) and manipulated the expiration prices, profiting from the exploitation of the erroneous prices.

It is noteworthy that when the project party's contract was created, the _transferOwnership status value of the attack address had already been set to true, allowing it to pass the contract security checks. Analysis shows that this attack address was likely one of the project party's management addresses, which was later controlled by hackers through social engineering attacks and other means to carry out this attack.

Latest News

Data: BTC breaks through 89000 USD

ChainCatcher

1月 25, 2026 12:30:28

Data: BTC falls below 90,000 USD

ChainCatcher

1月 24, 2026 03:36:41

Data: SOL falls below 130 USD

ChainCatcher

1月 24, 2026 02:30:14

Data: ETH falls below 3000 USD

ChainCatcher

1月 24, 2026 02:30:12

Data: SOL breaks through 130 USD

ChainCatcher

1月 24, 2026 01:30:10

Recent Fundraising

More
$8M 1月 29
$80M 1月 27

New Tokens

More
12月 24, 2025
12月 23, 2025
12月 20, 2025

Latest Updates on 𝕏

More