$305K Stolen via Aave V3 Module Vulnerability
An Aave V3 module vulnerability allowed an attacker to withdraw approximately $305,000 from two Safe multisig wallets. The attacker exploited an access control weakness in FlashLoopAdapter, a third-party adapter used for managing positions in Aave V3.
Aave founder Stani Kulechov clarified that the vulnerability did not affect the protocol itself but was related to the external third-party module.