Aave Adapter Exploit Drains $305K, Leaves V3 Unscathed
Aave's V3 protocol remained unaffected by an exploit that drained $305,000 from two Safe multisig wallets. The attack targeted a third-party adapter built on top of Aave, which allowed the attacker to control the router and transaction data used for swaps.
According to Stani Kulechov, Aave's founder, 'This is not Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3.'
The attacker exploited an access-control flaw in the FlashLoopAdapter contract to execute transactions through the victim Safes and drain wETH and collateral. Approximately 1,300 wrapped Ether (WETH) in debt was repaid during the attack to unlock collateral.