Summary
Ribbon Finance is an Ethereum-based DeFi protocol that pioneered Theta Vaults (DeFi Options Vaults) for structured yield products, later expanding into the Aevo derivatives exchange. The protocol has experienced multiple serious incidents including a $2.7 million oracle exploit in December 2025 whose recovery plan drew widespread community condemnation, a 2021 Sybil attack on its token airdrop by a connected venture capital firm, and a DNS hijacking in 2022. Its native token RBN lost approximately 90% of its value in 2025 alone and sits more than 99% below its all-time high.
Connected Entities
2 entities- + 2 more
Timeline(11 events)
2020-11-01
Ribbon Finance co-founded by Julian Koh and Ken Chan.
2021-05-01
Theta Vaults (DeFi Options Vaults) launched on Ethereum mainnet.
2021-10-08
Divergence Ventures researcher exposed for Sybil attack on RBN airdrop; approximately $2.5 million in tokens claimed via dozens of wallets. Funds returned same day.
2022-05-01
Protocol loses over $100 million in TVL amid Terra/LUNA collapse and crypto market panic.
2022-06-23
DNS hijacking attack on app.ribbon.finance; two users approve malicious contracts; vault funds unaffected.
2023-03-01
Ribbon Finance launches Aevo options exchange mainnet on custom Ethereum rollup.
2023-07-25
Ribbon DAO approves RGP-33 merging Ribbon Finance into Aevo with 99.68% of votes in favor; 1:1 RBN-to-AEVO token migration authorized.
2025-12-06
Aevo deploys oracle upgrade adding 18-decimal precision support for stETH, PAXG, LINK, and AAVE — inadvertently introducing decimal mismatch and access control vulnerability in legacy Ribbon vaults.
2025-12-12
Attacker exploits oracle vulnerability in legacy Ribbon DOV vaults, draining approximately $2.7 million across ETH, wstETH, USDC, and WBTC. Stolen funds distributed to 15 wallet addresses.
2025-12-13
Aevo halts all Ribbon vaults and proposes 19% haircut recovery plan, relying on assumed dormancy of inactive accounts to fund active users' partial compensation. Aevo restricts X replies to verified accounts amid community backlash.
2025-12-18
Aevo reportedly reverses initial recovery plan; affected vault depositors face 100% loss. All Ribbon vaults decommissioned with claims window through June 12, 2026.
Decision Log
- hash: 7y7CgYYNWCUqirMuVGRNJE7uFkfGJ2ukxHv7CrDsJHxH
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:19 AM
last updated: 5/26/2026, 7:54:24 PM
avoid.net — verified advice for a post-truth world