Aave External Adapter Hacked for Approximately $110,000 in Ethereum
A recent attack on an external adapter used by Aave has resulted in the theft of approximately $110,000 worth of Ethereum. The affected adapter, known as FlashLoopAdapter, is a third-party tool built on top of the decentralized finance (DeFi) lending protocol Aave V3.
According to SlowMist, a blockchain security firm, an access control vulnerability was discovered in the external adapter. The attacker exploited this weakness by creating a fake Safe contract that bypassed the adapter's authentication process.
The attacker then specified arbitrary transaction paths and call data to gain access to victims' Safe multisig wallets. Two multisig wallets were targeted in the process, resulting in the theft of approximately 114.09 Ethereum.
Aave founder Stani Kulechov has stated that this was not an issue with Aave V3 contracts but rather a third-party external adapter built on top of Aave. He emphasized that Aave V3 is completely unaffected by the attack.