Aave Tool Exploited for $300k Ethereum Heist
Crypto hackers have exploited a third-party tool built on Aave to steal approximately 114.09 ETH, worth over $300,000.
The attackers compromised two Safe multisig wallets through a flaw in the FlashLoopAdapter used with Aave v3 positions.
The exploit allowed the attacker to bypass the adapter's authentication checks, execute arbitrary calls, and drain collateral from the affected wallets.
Aave founder Stani Kulechov emphasized that the incident did not involve Aave v3's core smart contracts, stating 'This is not Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3.'