[GoPlus: Ribbon Finance Suspected Attack Due to Management Address Being Hacked]
The GoPlus Chinese community analyzed the principle behind the Ribbon Finance attack, pointing out that the attacker upgraded a malicious contract via address 0x657CDE, setting the expiration date of stETH, Aave, PAXG, LINK to December 12, 2025, 16:00:00 (UTC+8) and tampered with prices to profit. Analysis shows that the _transferOwnership status of this address was already set to true when the contract was created, suggesting that the project's management address may have been compromised by hackers.