LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

Aave Founder Confirms V3 Unaffected by Third-Party Adapter Exploit Draining $305K

Cointelegraph · Ezra Reguerra

Aave founder Stani Kulechov clarified that Aave V3 itself was not impacted by a security breach wherein approximately $305,000 was drained from two Safe multisig wallets via a third-party adapter. The attacker exploited an authorization bypass and controlled transaction data through the external adapter, resulting in the loss, Kulechov emphasized.

Details of the Attack and Attacker Actions

Blockchain security company SlowMist reported that the attacker targeted a module responsible for opening and closing leveraged positions on Aave V3 via Safe multisig wallets.

The exploit involved an access control vulnerability allowing a fraudulent Safe contract to bypass the adapter’s authorization check.

The adapter also granted the caller control over the router and transaction data used for swaps, which the attacker leveraged to execute transactions through the victims’ Safes, draining weETH and collateral.

Losses and Aave’s Response

Approximately 1,300 wrapped Ether (WETH) debt was repaid during the attack to unlock collateral.

Ultimately, about 114.09 ETH, valued around $305,000, was stolen from two Safe multisig wallets.

Aave founder Stani Kulechov emphasized on X that the issue stemmed from the third-party adapter, not the Aave V3 contracts themselves, and that Aave V3 suffered no direct loss.

SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker’s wallet but confirmed no damages to Aave V3 protocol.

Why it matters

This incident highlights the inherent risks associated with third-party tools and adapters layered on top of major DeFi protocols. While the core Aave V3 contract remained secure, vulnerabilities in an external module caused substantial user losses, underscoring the need for rigorous auditing and caution when integrating external components within cryptocurrency ecosystems.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗