Aave V3 Hit by $305,000 Withdrawal via Third-Party Module Vulnerability
Aave V3, a decentralized lending protocol, suffered a vulnerability exploit that resulted in a significant withdrawal of funds. An attacker exploited an access control vulnerability in the FlashLoopAdapter module, withdrawing approximately $305,000 from two Safe multisig wallets. The affected wallets were used for managing positions in Aave V3.
Aave founder Stani Kulechov clarified that the vulnerability did not affect the protocol itself, but rather an external third-party adapter built on top of the protocol. This distinction is crucial, as it suggests that the issue is isolated to the specific module and not a broader problem with the Aave V3 protocol.