Aave Hack Targets External Adapter, Results in $305,000 Loss
Aave, a decentralized-finance lending protocol, has been hit by a hack that targeted an external adapter built on its platform. The attack, which resulted in user losses of about $305,000, was attributed to an access-control vulnerability in FlashLoopAdapter, a third-party tool used for leveraged positions on Aave V3. The hacker exploited a fake Safe contract to bypass the adapter's authentication process, allowing them to steal assets from victims' Safe multisignature wallets.
According to Aave's founder, Stani Kulechov, the issue occurred in a third-party external adapter built on top of Aave, not in the Aave V3 contracts. He emphasized that Aave V3 was not affected by the hack, and the protocol itself remains secure.
The hack has raised concerns about the security of external adapters built on top of Aave, and the importance of robust access controls in preventing similar attacks in the future.