Aave founder Stani Kulechov said Aave V3 was not affected by an exploit that drained roughly $305,000 from two Safe multisig wallets. According to Kulechov, the issue did not involve the Aave V3 core contract, but a third-party external adapter built on top of the lending protocol.
Blockchain security firm SlowMist said the attacker targeted a module used to open and close leveraged Aave V3 positions through Safe wallets. The flaw was an access-control issue that let a fake Safe contract pass the adapter’s authorization check. SlowMist also said the adapter let the caller choose the router and transaction data used for swaps, which the attacker used to execute transactions through the victim wallets and remove weETH and collateral.
During the attack, about 1,300 WETH in debt was repaid to unlock collateral, SlowMist said. The attacker ultimately stole around 114.09 ETH, worth about $305,000, from the two Safe multisigs. SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker’s wallet, and said it found no losses to Aave V3 itself.
Aave founder Stani Kulechov said Aave V3 was not affected by an exploit that drained about $305,000 from two Safe multisig wallets through a third-party adapter built on top of the lending protocol.
In a post on X, Kulechov said: "This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3."
Attack targeted a module tied to leveraged Aave V3 positions
Blockchain security firm SlowMist said the attacker went after a module used to open and close leveraged Aave V3 positions through Safe wallets. The firm said the attacker exploited an access-control flaw that allowed a fake Safe contract to pass the adapter’s authorization check.
SlowMist said the adapter also let the caller control the router and the transaction data used for swaps. The attacker used that function to execute transactions through the victim Safes and drain weETH and collateral.
About 1,300 WETH in debt was repaid during the exploit
According to SlowMist, about 1,300 wrapped Ether (WETH) in debt was repaid during the attack to unlock collateral. The attacker ultimately stole about 114.09 Ether (ETH), worth roughly $305,000, from two Safe multisigs.
SlowMist said it identified the vulnerable FlashLoopAdapter contract and the attacker’s wallet. The firm did not report any losses to Aave V3 itself.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.