Post‑Mortem: Aerodrome Lend Vault Incident on Base

All user funds are safe.

Date: January 30, 2026
Network: Base
Status: Aerodrome Lend is currently paused (new deposits/borrows disabled)

On January 29, 2026 we announced support for Aerodrome concentrated liquidity positions on Base:
https://paragraph.com/@revertfinance/revert-lend-now-supports-aerodrome-on-base

A few hours later, we received and verified a report of an exploit affecting the newly deployed Aerodrome Lend vault. We immediately disabled new deposits and new borrows via our emergency multisig and communicated the pause publicly:
https://x.com/revertfinance/status/2017087480772600157


TL;DR

  • All user funds are safe.

  • The USDC in the affected vault was 100% Revert team capital (no third‑party user deposits were in the pool at the time).

  • Only the Aerodrome Lend vault on Base was affected. No other Revert vaults/products were impacted.

  • This deployment had three independent audits (Cantina, PeckShield, HYDN). We are implementing fixes and will not re‑enable Aerodrome Lend without additional independent review/audit of the changes.


Impact

  • Loss: ~50,101.744193 USDC (protocol‑owned / Revert team funds)

  • User impact: none (no user funds in the affected pool)

  • Affected component: Aerodrome Lend vault integration (Base)

Onchain transactions (Base)

#

Tx

Block

Time (UTC)

Amount

1

https://basescan.org/tx/0x10429eaeb479f9149854e4aeb978a35ac02d9688f6e22371712b3878c63a64ab

41475479

02:31

49,000 USDC

2

https://basescan.org/tx/0xe7f8405d3f10d431ce1958942dcf877cf1dcbea4f2a2a918fa8499d778295ee3

41477209

03:29

1,101.744193 USDC

A second exploit transaction occurred ~58 minutes after the first, from a different address.


Timeline (UTC)

  • Jan 29, 2026: Aerodrome support announced (launch post linked above)

  • Jan 30, 2026 ~02:31: Exploit transaction #1

  • Jan 30, 2026 ~03:29: Exploit transaction #2

  • Shortly after verification: New deposits and borrows disabled via emergency multisig; Aerodrome Lend paused

  • Jan 30, 2026 14:14:21: Onchain recovery outreach sent to the address thatcontrol the exploited funds.


What happened (technical overview)

Aerodrome Lend allows Aerodrome Slipstream concentrated liquidity positions (NFTs) to be used as collateral in a lending vault, while optionally being staked for gauge rewards and autocompounding.

This incident was caused by an end‑to‑end invariant gap across multiple contracts involved in that flow.

The staking/automation layer (used to stake positions and execute position-management operations) included a pathway that allowed the position owner to execute operations that could materially change the position, even when that position was flagged as a vault-collateralized position.

In short, the attacker was able to withdraw liquidity from a collateralized (and staked) LP position while leaving the vault with an NFT that still existed but no longer represented the expected collateral value for the outstanding loan.

Attack flow (simplified)

  1. Flash‑loan funds were used to mint an Aerodrome Slipstream LP position (NFT).

  2. The attacker deposited the NFT into the Aerodrome Lend vault as collateral.

  3. The attacker borrowed USDC against that collateral.

  4. The position was staked through the vault’s staking/manager flow.

  5. The attacker used a GaugeManager execution path (via a utility contract) that temporarily unstakes the NFT and executes position‑management instructions.

  6. That execution path did not enforce the constraints required for positions backing active debt, allowing liquidity to be withdrawn and routed to the attacker.

  7. The flash loan was repaid and the borrowed USDC became profit.


Root cause

The root cause was a missing safety constraint in the staking/management layer: a collateralized position with active debt could still be modified through an execution path in a way that reduced its collateral value without the vault preventing the action at the time it happened.


Immediate response

  • Verified the report and confirmed the issue onchain.

  • Disabled new deposits and new borrows for the Aerodrome Lend vault via emergency multisig.

  • Communicated the pause publicly and began remediation.


Remediation & next steps

Aerodrome Lend will remain paused while we:

  • implement fixes to ensure collateralized positions cannot be modified in ways that break collateral backing,

  • complete additional internal review and testing of the Aerodrome integration and surrounding flows,

  • commission additional independent security review/audit specifically focused on the incident root cause and the final remediation.

We will publish follow‑up updates as we complete these steps. Aerodrome Lend will not be re‑enabled until the fixes are deployed and the additional independent review/audit is complete.


Contracts involved

Contract

Address

Role

Revert Lend Vault

0x22CE292d882C7799183949509B011512352454cB

Lending vault

GaugeManager

0x66a2481b784Cf26103441cA6067F997f90d3E129

Gauge staking manager

V3Utils

0x7D1F9FC22bed0798cda3fdb18b14a96fc838B9E1

Position utility contract

Aerodrome Gauge

0xfd548a1C01f1547b305313e4D42BD9C714EFdF6a

LP staking gauge cont

Morpho

0xBBBBBbbBBb9cC5e90e3b3Af64bdAF62C37EEFFCb

Flash loan provider


Security reviews / audits

Prior to launch, the Revert Lend deployment and supporting components underwent three independent audits/reviews:

Audits reduce risk, but they are not a guarantee. We take responsibility for this incident and are adding additional review/audit before re‑enabling Aerodrome Lend.

After the incident, HYDN Security proactively reached out and assisted our team during incident response and remediation planning.


Thank you / reporting

Thank you to the reporter who raised the issue quickly. If you believe you have found a vulnerability, please disclose it responsibly via the security contact listed in our documentation.