Aave Adapter Hack Stuns Crypto Community with $305,000 Losses
Aave, a popular decentralized-finance lending protocol, has been hit by a hack that targeted an external adapter built on its platform. The attack resulted in losses of approximately $305,000, with two wallets losing around 114.09 Ether. The hack stemmed from an access-control vulnerability in FlashLoopAdapter, a third-party tool used for leveraged positions on Aave V3.
The attacker exploited the vulnerability by using a fake Safe contract to bypass the adapter's authentication process, allowing them to steal assets from victims' Safe multisignature wallets. Aave founder Stani Kulechov stated that the issue occurred in a third-party external adapter built on top of Aave, not in the Aave V3 contracts. He emphasized that Aave V3 was not affected by the incident.
The hack has raised concerns about the security of third-party adapters on the Aave platform. It remains to be seen how Aave will address the issue and prevent similar attacks in the future.