Aave v3 Lending Protocol Unaffected by Third-Party Adapter Exploit
A recent security incident involving a third-party adapter used with Aave's v3 lending protocol has exposed potential risks tied to external integrations rather than the core protocol itself.
According to Aave founder Stani Kulechov, the incident does not affect Aave v3 itself, as the vulnerable component is an external adapter built on top of the protocol, not the core contract.
The attack, which targeted a module used to open and close leveraged Aave v3 positions through Safe wallets, exploited an access-control flaw in the FlashLoopAdapter contract.
The attacker was able to steal about 114.09 Ether, worth around $305,000, from two Safe multisigs by executing transactions through the victim Safes and repaying debt to unlock collateral.