Aave Third-Party Adapter Exploited for 114 ETH, Worth Over $300,000
A recent exploit on Aave's third-party adapter, known as the FlashLoopAdapter, resulted in the theft of approximately 114 ETH, worth over $300,000. This vulnerability allowed an attacker to bypass authentication checks and drain collateral from affected wallets. Aave founder Stani Kulechov confirmed that the core contracts of Aave v3 remained unaffected by the exploit, which targeted external infrastructure layered on top of the protocol.
The vulnerability was discovered by blockchain security firm SlowMist, who found that the attacker created a fake Safe contract that spoofed the authentication check, allowing them to execute arbitrary calls and drain collateral. SlowMist estimated the direct loss at around 114.09 ETH and noted that roughly 1,300 WETH of debt was repaid during the attack to unlock collateral tied to the positions.
The incident highlights the risk of external integrations creating separate attack surfaces, even when the core protocol contracts remain secure. Aave's total value locked is over $33 billion, making this exploit a significant concern for the decentralized lending protocol.
Aave is working to identify additional affected positions and prevent further attacks. The immediate exposure appears contained to users of the vulnerable adapter, but the incident serves as a reminder of the importance of securing external integrations in decentralized finance.