Aave v3 Remains Secure After $305K Exploit via Third-Party Adapter
- An exploit drained approximately $305,000 from two Safe multisig wallets using a third-party adapter on the Aave protocol.
- The attack targeted a module for managing leveraged Aave v3 positions through Safe wallets, exploiting an access-control vulnerability.
- Around 1,300 wrapped Ether (WETH) in debt was repaid during the attack to unlock collateral, leading to the theft of about 114.09 Ether (ETH).
- Blockchain security firm SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker’s wallet but confirmed no losses to Aave v3 itself.
The incident highlights vulnerabilities associated with third-party integrations in decentralized finance (DeFi). Despite this exploit, Aave v3 remains unaffected as confirmed by founder Stani Kulechov.
Ultimately, around $305,000 was stolen due to an exploit of a third-party adapter, but Aave v3 itself experienced no impact from this event. (Source)