Key facts
- Aave founder Stani Kulechov stated Aave v3 was unaffected by a recent exploit.
- An attacker drained about $305,000 from two Safe multisig wallets.
- The exploit targeted a third-party adapter, not the core Aave v3 contracts.
Aave founder Stani Kulechov stated that the Aave v3 protocol was not affected by a recent exploit. The attack, which drained approximately $305,000 from two Safe multisig wallets, targeted a third-party adapter built on top of Aave, not the core Aave v3 contracts.
The incident highlights the risks associated with third-party integrations in decentralized finance, even when the core protocol remains secure. While Aave v3 was not directly compromised, the exploit demonstrates how vulnerabilities in connected services can lead to significant financial losses for users.
Aave founder Stani Kulechov has stated that the Aave v3 protocol remained unaffected after an exploit resulted in the loss of approximately $305,000 from two Safe multisig wallets. The attack targeted a third-party adapter built on top of the Aave protocol, rather than the core Aave v3 smart contracts.
According to blockchain security firm SlowMist, the exploit involved a module designed for opening and closing leveraged Aave v3 positions via Safe wallets. The attacker leveraged an access-control vulnerability, allowing a fraudulent Safe contract to bypass the adapter's authorization checks. This allowed the attacker to control the router and transaction data, enabling them to execute unauthorized transactions through the victim Safe wallets and drain collateral.
During the attack, approximately 1,300 wrapped Ether (WETH) in debt was repaid to unlock collateral. The attacker ultimately made off with about 114.09 Ether (ETH), valued at roughly $305,000. SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker's wallet but confirmed no losses to Aave v3 itself.
Pick the topics you care about. Get only what matters, on your cadence.