Aave v3 Protocol Unscathed by $305,000 Third-Party Adapter Exploit
Aave's v3 lending protocol was unaffected by an attacker who exploited a third-party adapter used by two Safe multisig wallets, taking around $305,000 in Ether. Stani Kulechov, Aave's founder, stated that the core v3 contracts were not compromised.
The attack targeted FlashLoopAdapter, a module designed to open and close leveraged positions on Aave v3 through Safe wallets. The weakness was in the adapter's access controls rather than Aave's lending contracts or Safe's underlying multisignature architecture.
According to SlowMist, the attacker spoofed the response from the fake Safe contract, allowing it to interact with the adapter and execute transactions through legitimate Safes. This resulted in around 1,300 WETH being repaid as part of the attack, unlocking WEETH and other collateral.