Aave Adapter Exploit Drains $305K, V3 Remains Unscathed
Aave founder Stani Kulechov has confirmed that the lending protocol's V3 was not affected by an exploit that drained around $305,000 from two Safe multisig wallets. The attack targeted a third-party adapter built on top of Aave, which allowed an attacker to execute transactions and drain weETH and collateral.
The security firm SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker's wallet but reported no losses to Aave V3 itself. During the attack, around 1,300 wrapped Ether (WETH) in debt was repaid to unlock collateral, resulting in the theft of approximately 114.09 ETH, worth around $305,000.
Kulechov emphasized that the issue was with the external adapter and not Aave V3 itself, stating 'This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.'