{"investigation":{"slug":"aperture-lm","entity_name":"Aperture LM","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Aperture LM (also marketed as Aperture Finance) is a multi-chain DeFi liquidity management protocol that launched in 2022 and raised $12 million at a reported $250 million valuation. On January 25, 2026, the protocol suffered a critical smart contract exploit due to insufficient input validation in its V3 and V4 helper modules, resulting in $3.67 million stolen from Aperture directly and contributing to a combined ~$17 million loss across a coordinated attack that also hit SwapNet. Stolen funds were laundered through Tornado Cash, no public compensation plan for affected users has been confirmed, and the protocol's closed-source contract architecture was identified as a compounding risk factor that hindered independent security review.","sections":[{"content":"On January 25, 2026, Aperture Finance suffered a targeted exploit across Ethereum, Arbitrum, Base, and BNB Chain. The root cause was an arbitrary-call vulnerability in the protocol's V3/V4 helper module (function 0x67b34120 / internal function 0x1d33). This module executed low-level external calls using user-supplied calldata without enforcing restrictions on the call target or function selector. Attackers crafted malicious calldata directing the protocol to call transferFrom on ERC-20 token contracts, exploiting pre-existing infinite approvals granted by users. This drained ERC-20 tokens and enabled unauthorized transfers of Uniswap V3 position NFTs without compromising private keys. The primary victim contract on Ethereum mainnet was 0xD83d960deBEC397fB149b51F8F37DD3B5CFA8913. The attack contract used was 0x5c92884dFE0795db5ee095E68414d6aaBf398130, and the primary attacker address identified was 0xe3e73f1e6ace2b27891d41369919e8f57129e8ea. Losses attributable to Aperture Finance totaled approximately $3.67 million USD. The same attacker class simultaneously exploited SwapNet using an analogous vulnerability, bringing combined losses to approximately $17 million. BlockSec confirmed both incidents stemmed from the same class of insufficient input validation vulnerability. Security firm PeckShield first flagged the suspicious transactions publicly.","heading":"January 2026 Smart Contract Exploit","sources":[{"url":"https://blocksec.com/blog/17m-closed-source-smart-contract-exploit-arbitrary-call-swapnet-aperture","name":"blocksec.com","type":"other","credibility":3},{"url":"https://coinpedia.org/news/defi-hack-alert-aperture-finance-smart-contract-exploit-suffers-3-67m-loss/","name":"coinpedia.org","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/aperture-finance-hack-analysis-22dca439ff33","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://coinfomania.com/aperture-finance-reports-exploit-and-urges-users-to-revoke-access/","name":"coinfomania.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the attacker converted stolen assets to ETH and deposited approximately 1,242.7 ETH (valued at approximately $2.4 million at the time) into Tornado Cash, structured in 10 ETH and 100 ETH increments to obscure the trail. AMLBot's on-chain forensic analysis identified cross-chain bridging from Base to Ethereum Mainnet via Relay Protocol and Superbridge as a secondary laundering step. Fresh intermediary wallets were created on Ethereum Mainnet after the bridge transfers, consistent with professional money-laundering tradecraft. The AMLBot report further noted that one secondary attacker address was linked to the Li.Fi Protocol/Jumper Exchange exploiter network, suggesting organized threat actors specializing in approval-abuse vulnerabilities. As of the time of reporting, no funds have been publicly recovered.","heading":"Fund Laundering via Tornado Cash","sources":[{"url":"https://blog.amlbot.com/13-5m-lost-in-aperture-finance-swapnet-exploit-full-on-chain-breakdown/","name":"blog.amlbot.com","type":"other","credibility":3},{"url":"https://www.mexc.com/news/643634","name":"mexc.com","type":"other","credibility":3},{"url":"https://coinpedia.org/news/defi-hack-alert-aperture-finance-smart-contract-exploit-suffers-3-67m-loss/","name":"coinpedia.org","type":"other","credibility":3}],"severity":"medium"},{"content":"BlockSec and SolidityScan researchers independently noted that Aperture Finance's smart contracts are closed-source, requiring bytecode decompilation to analyze deployed logic. This limited pre-exploit community scrutiny and post-incident forensic speed. Aperture Finance's published security audit page documents six historical audits: Veridise (September 2023, UniV3 fork deployment), Narya.ai (July 2023, V3 automation contracts), Narya.ai (May 2023, initial V3 contracts), Oak Security/Solidified (August 2022, Avalanche PDN Strategies), Oak Security (April 2022, cross-chain module), and Oak Security (January 2022, Terra DNS). Critically, none of the documented audits explicitly cover the V3/V4 helper module containing the exploited function 0x67b34120, and no audit post-dating September 2023 is listed. The deployed contracts that were exploited in January 2026 do not appear to have undergone a corresponding public audit covering the specific functions that were attacked.","heading":"Closed-Source Contracts and Audit Gaps","sources":[{"url":"https://docs.aperture.finance/docs/transparency/security-audit","name":"docs.aperture.finance","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/aperture-finance-hack-analysis-22dca439ff33","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://blocksec.com/blog/17m-closed-source-smart-contract-exploit-arbitrary-call-swapnet-aperture","name":"blocksec.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Immediately following the exploit, Aperture Finance halted core frontend functions to prevent new wallet approvals. The team issued emergency guidance directing users to revoke both ERC-20 token approvals and ERC-721 liquidity position approvals tied to the compromised contract address (0xD83d960deBEC397fB149b51F8F37DD3B5CFA8913) using Etherscan's approval checker or Revoke.cash. The team stated it was working with external security partners to investigate the root cause and committed to releasing a comprehensive post-mortem. As of the available reporting, no formal public compensation plan for affected users has been confirmed, and the promised post-mortem had not been publicly verified as published in detail.","heading":"Team Response and User Remediation","sources":[{"url":"https://x.com/ApertureFinance/status/2015938720453820752","name":"x.com","type":"other","credibility":3},{"url":"https://coinfomania.com/aperture-finance-reports-exploit-and-urges-users-to-revoke-access/","name":"coinfomania.com","type":"other","credibility":3},{"url":"https://cryptoadventure.com/aperture-finance-reports-v3-v4-contract-exploit-halts-front-end-functions/","name":"cryptoadventure.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Aperture Finance launched its native APTR token on May 31, 2024, with a reported initial valuation of $250 million following $12 million raised across multiple funding rounds. The token reached an all-time high of approximately $0.12497 on June 10, 2024. By 2025, APTR had declined approximately 99.25% year-over-year, trading at roughly $0.00005 as of early 2026. The January 2026 exploit contributed to continued negative price pressure. Current market data from CoinMarketCap lists the token at negligible value relative to its peak. The project reports it has processed over $3.7 billion in intent volume and served approximately 344,634 active wallets historically, though TVL as tracked by third-party analytics (AlphaGrowth) stood at approximately $12,871 at the time of this investigation — a fraction of historical levels.","heading":"Token Performance and Market Impact","sources":[{"url":"https://coinmarketcap.com/currencies/aperture-finance/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://alphagrowth.io/aperture-lm","name":"alphagrowth.io","type":"other","credibility":3},{"url":"https://medium.com/@aperturefinance/aperture-finance-aptr-fca15735d698","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Aperture LM (Aperture Finance) was founded in 2022 and operates as a cross-chain DeFi liquidity management platform. It offers AI-powered intent-based trading through an IntentsGPT interface and manages Uniswap V3 liquidity positions on behalf of users across Ethereum, Arbitrum, Base, BNB Chain, and Avalanche, with prior deployments on Terra. The project raised a total of $12 million across seed and Series A rounds and was valued at $250 million at its Series A. The founding team includes Lian Zhu, Gao Han, and Peiqian Li, whose professional backgrounds have been described in promotional materials as drawing from Google, Netflix, and Wall Street. The platform's flagship product, ApertureSwap, integrates with Uniswap and PancakeSwap. The protocol's use of a gasless transaction model requires users to grant token approvals — approvals that were subsequently weaponized in the January 2026 exploit.","heading":"Protocol Background and Funding","sources":[{"url":"https://defillama.com/protocol/aperture-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/academy/article/what-is-aperture-finance","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://alphagrowth.io/aperture-lm","name":"alphagrowth.io","type":"other","credibility":3},{"url":"https://chainbroker.io/projects/aperture-finance/","name":"chainbroker.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Aperture LM has been flagged by on-chain investigator ZachXBT, though the specific content and date of ZachXBT's public statement regarding this entity could not be independently verified through publicly accessible primary sources at the time of this investigation. ZachXBT (zachxbt.mirror.xyz) maintains a public record of investigations into DeFi exploits and fraud. The January 2026 exploit received broad coverage from security firms including PeckShield, BlockSec, SolidityScan, and AMLBot, all of which are credible secondary sources corroborating the seriousness of the incident. Users are advised to treat any ZachXBT flag as a signal warranting heightened due diligence.","heading":"ZachXBT Flagging","sources":[{"url":"https://zachxbt.mirror.xyz/","name":"zachxbt.mirror.xyz","type":"other","credibility":3},{"url":"https://blocksec.com/blog/17m-closed-source-smart-contract-exploit-arbitrary-call-swapnet-aperture","name":"blocksec.com","type":"other","credibility":3},{"url":"https://coinpedia.org/news/defi-hack-alert-aperture-finance-smart-contract-exploit-suffers-3-67m-loss/","name":"coinpedia.org","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022","event":"Aperture Finance founded; initial audit of Terra DNS module by Oak Security completed March 2022.","source":"","date_original":"2022-01-01"},{"date":"2022-08","event":"Oak Security/Solidified audit of Avalanche PDN Strategies completed September 2022.","source":"","date_original":"2022-08-01"},{"date":"2023-05-08","event":"First Narya.ai audit of UniV3 automation contracts completed.","source":""},{"date":"2023-07-03","event":"Second Narya.ai audit of UniV3 automation contracts completed.","source":""},{"date":"2023-09-29","event":"Veridise audit of UniV3 fork deployment completed — last documented audit on record.","source":""},{"date":"2024-05-31","event":"APTR token officially launched on Ethereum, Arbitrum, and Mantle Network.","source":""},{"date":"2024-06-10","event":"APTR token reaches all-time high of approximately $0.12497.","source":""},{"date":"2025-12-31","event":"APTR token ends 2025 down approximately 99.25% year-over-year, trading near $0.00005.","source":""},{"date":"2026-01-25","event":"Arbitrary-call vulnerability in Aperture Finance V3/V4 helper module exploited across Ethereum, Arbitrum, Base, and BNB Chain; $3.67 million stolen. Same attacker simultaneously exploits SwapNet for ~$13.4 million; combined losses reach ~$17 million. Exploit first flagged by PeckShield.","source":""},{"date":"2026-01-25","event":"Aperture Finance halts frontend functions, issues emergency advisory urging users to revoke approvals for contract 0xD83d960deBEC397fB149b51F8F37DD3B5CFA8913.","source":""},{"date":"2026-01-27","event":"Attacker deposits approximately 1,242.7 ETH (~$2.4 million) into Tornado Cash in structured batches. AMLBot publishes initial on-chain findings.","source":""},{"date":"2026-01-28","event":"BlockSec publishes detailed technical analysis of both the Aperture Finance and SwapNet exploits, attributing root cause to insufficient input validation in closed-source contracts.","source":""},{"date":"2026-02-03","event":"AMLBot publishes full on-chain forensic breakdown; secondary attacker linked to Li.Fi/Jumper Exchange exploiter network.","source":""}],"sources_used":[{"url":"https://blocksec.com/blog/17m-closed-source-smart-contract-exploit-arbitrary-call-swapnet-aperture","name":"blocksec.com","type":"other","archive_url":"http://web.archive.org/web/20260825171818/https://blocksec.com/blog/17m-closed-source-smart-contract-exploit-arbitrary-call-swapnet-aperture","credibility":3,"archive_timestamp":"2026-08-25T17:18:18+00:00"},{"url":"https://coinpedia.org/news/defi-hack-alert-aperture-finance-smart-contract-exploit-suffers-3-67m-loss/","name":"coinpedia.org","type":"other","archive_url":"http://web.archive.org/web/20260210202711/https://coinpedia.org/news/defi-hack-alert-aperture-finance-smart-contract-exploit-suffers-3-67m-loss/","credibility":3,"archive_timestamp":"2026-02-10T20:27:11+00:00"},{"url":"https://blog.solidityscan.com/aperture-finance-hack-analysis-22dca439ff33","name":"blog.solidityscan.com","type":"other","archive_url":"http://web.archive.org/web/20260512180330/https://blog.solidityscan.com/aperture-finance-hack-analysis-22dca439ff33/","credibility":3,"archive_timestamp":"2026-05-12T18:03:30+00:00"},{"url":"https://coinfomania.com/aperture-finance-reports-exploit-and-urges-users-to-revoke-access/","name":"coinfomania.com","type":"other","archive_url":"https://web.archive.org/web/20260829175226/https://coinfomania.com/aperture-finance-reports-exploit-and-urges-users-to-revoke-access/","credibility":3,"archive_timestamp":"2026-08-29T17:52:26+00:00"},{"url":"https://blog.amlbot.com/13-5m-lost-in-aperture-finance-swapnet-exploit-full-on-chain-breakdown/","name":"blog.amlbot.com","type":"other","archive_url":"http://web.archive.org/web/20260512185649/https://blog.amlbot.com/13-5m-lost-in-aperture-finance-swapnet-exploit-full-on-chain-breakdown/","credibility":3,"archive_timestamp":"2026-05-12T18:56:49+00:00"},{"url":"https://www.mexc.com/news/643634","name":"mexc.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:gone","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.aperture.finance/docs/transparency/security-audit","name":"docs.aperture.finance","type":"other","archive_url":"http://web.archive.org/web/20260418041452/https://docs.aperture.finance/docs/transparency/security-audit","credibility":3,"archive_timestamp":"2026-04-18T04:14:52+00:00"},{"url":"https://x.com/ApertureFinance/status/2015938720453820752","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cryptoadventure.com/aperture-finance-reports-v3-v4-contract-exploit-halts-front-end-functions/","name":"cryptoadventure.com","type":"other","archive_url":"http://web.archive.org/web/20260829074619/https://cryptoadventure.com/aperture-finance-reports-v3-v4-contract-exploit-halts-front-end-functions/","credibility":3,"archive_timestamp":"2026-08-29T07:46:19+00:00"},{"url":"https://coinmarketcap.com/currencies/aperture-finance/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260308081512/https://coinmarketcap.com/currencies/aperture-finance/","credibility":3,"archive_timestamp":"2026-03-08T08:15:12+00:00"},{"url":"https://alphagrowth.io/aperture-lm","name":"alphagrowth.io","type":"other","archive_url":"http://web.archive.org/web/20250911002752/https://alphagrowth.io/aperture-lm","credibility":3,"archive_timestamp":"2025-09-11T00:27:52+00:00"},{"url":"https://medium.com/@aperturefinance/aperture-finance-aptr-fca15735d698","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/aperture-finance","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20251014042648/https://defillama.com/protocol/aperture-finance","credibility":3,"archive_timestamp":"2025-10-14T04:26:48+00:00"},{"url":"https://coinmarketcap.com/academy/article/what-is-aperture-finance","name":"coinmarketcap.com","type":"other","archive_url":"https://web.archive.org/web/20260829112911/https://coinmarketcap.com/academy/article/what-is-aperture-finance","credibility":3,"archive_timestamp":"2026-08-29T11:29:11+00:00"},{"url":"https://chainbroker.io/projects/aperture-finance/","name":"chainbroker.io","type":"other","archive_url":"http://web.archive.org/web/20250905123433/https://chainbroker.io/projects/aperture-finance/","credibility":3,"archive_timestamp":"2025-09-05T12:34:33+00:00"},{"url":"https://zachxbt.mirror.xyz/","name":"zachxbt.mirror.xyz","type":"other","archive_url":"http://web.archive.org/web/20251025091919/https://zachxbt.mirror.xyz/","credibility":3,"archive_timestamp":"2025-10-25T09:19:19+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:19.080821+00:00","updated_at":"2026-08-29T18:16:45.709404+00:00"}}