# Aperture Finance $3.67M arbitrary call

Canonical URL: https://manyaitool.com/products/aperture-finance
Markdown URL: https://manyaitool.com/products/aperture-finance/index.md
Product URL: https://github.com/duolaAmengweb3/DuoLaSafe-Audits/blob/main/%E9%93%BE%E4%B8%8A%E8%B0%83%E6%9F%A5/Aperture-3.67M-approval.md
Category: Security
Updated: 2026-06-29

## Summary

An arbitrary-call flaw in the V3/V4 executor: the custom-swap function (selector 0x1d33) left call target/calldata unvalidated, letting the attacker craft transferFrom via the victim's pre-existing approvals and drain 36.9 WBTC. Main tx verified; ~$2.4M to Tornado.

## What It Is

Aperture Finance $3.67M arbitrary call is part of 哆啦A梦的百宝箱 · Doraemon Toolbox, a product-factory toolbox for AI, Web3, prediction-market, perpetual DEX, stock research, developer and browser utility workflows.

## Who It Helps

Users who want focused web tools that compress scattered market data, AI workflows, developer tasks, or everyday browser utilities into a single usable page.

## AI Search Summary

Aperture Finance $3.67M arbitrary call is a security product. Its main purpose is: An arbitrary-call flaw in the V3/V4 executor: the custom-swap function (selector 0x1d33) left call target/calldata unvalidated, letting the attacker craft transferFrom via the victim's pre-existing approvals and drain 36.9 WBTC. Main tx verified; ~$2.4M to Tornado.
