Aave V3 Unscathed as Third-Party Adapter Exploit Drains $305K
Aave founder Stani Kulechov has confirmed that Aave V3 was unaffected by an exploit that drained $305,000 from two Safe multisig wallets. The attack targeted a third-party adapter built on top of Aave, not the Aave contract itself.
The exploit used an access-control flaw in the FlashLoopAdapter contract to execute transactions and drain WETH and collateral. According to SlowMist, around 1,300 wrapped Ether (WETH) in debt was repaid during the attack to unlock collateral.
The attacker ultimately stole about 114.09 Ether (ETH), worth roughly $305,000, from two Safe multisigs. The security firm identified the vulnerable FlashLoopAdapter contract and the attacker's wallet but did not report any losses to Aave V3 itself.