Third-Party Adapter Exploit Siphons $305K, But Aave V3 Remains Secure, Founder Confirms

Third-Party Adapter Exploit Siphons $305K, But Aave V3 Remains Secure, Founder Confirms

Stani Kulechov, founder of Aave, confirmed that the core Aave v3 protocol remained secure following an exploit of a third-party adapter that resulted in approximately $305,000 being drained from two Safe multisig wallets.

Stani Kulechov, the founder of Aave, has confirmed that the Aave v3 protocol remained completely unaffected following a security exploit that resulted in approximately $305,000 being siphoned from two Safe multisig wallets via a third-party adapter constructed on top of the decentralized lending protocol.

"This is not Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3," Kulechov said on X.

According to blockchain security company SlowMist, the exploit specifically targeted a module designed to open and close leveraged Aave v3 positions through Safe wallets. The malicious actor took advantage of an access-control vulnerability that enabled a fraudulent Safe contract to successfully pass through the adapter's authorization verification process.

The security firm SlowMist reported that the adapter permitted the caller to manipulate both the router and the transaction data utilized for swaps. The perpetrator leveraged this specific functionality to carry out transactions through the compromised Safe wallets and extract weETH along with other collateral assets.

Approximately 1,300 wrapped Ether (WETH) in outstanding debt was settled during the course of the attack in order to release the locked collateral, SlowMist reported. The malicious actor successfully extracted approximately 114.09 Ether (ETH), valued at roughly $305,000, from the two compromised Safe multisig wallets.

SlowMist successfully identified both the compromised FlashLoopAdapter contract and the wallet address belonging to the attacker, though the firm confirmed that no funds were lost from the Aave v3 protocol itself.

← Zurück zum Blog