Aave Hack Exposes Vulnerability in External Adapter
A recent hack on Ethereum compromised two Safe wallets, resulting in an estimated net loss of $305,000. The vulnerability was attributed to a custom FlashLoopAdapter used for managing leveraged Aave V3 positions. The attacker spoofed a Safe authentication check and exploited the adapter's open() and close() functions to unlock collateral.
The attack, which occurred on October 1 at 15:08:57 UTC, involved a malicious contract posing as a Safe and passing an intended authentication check. This allowed the attacker to access wallet-controlled collateral and withdraw approximately 114.09 ETH, valued at around $305,000.
Aave founder Stani Kulechov stated that the vulnerable component was an external integration rather than an Aave V3 contract and had 'zero effect on Aave v3.'