Aave v3 Unscathed by Third-Party Adapter Exploit That Drained $305K
Aave founder Stani Kulechov has confirmed that Aave v3 was not affected by an exploit that drained around $305,000 from two Safe multisig wallets. The attack targeted a third-party adapter built on top of Aave, which allowed the attacker to control router and transaction data used for swaps.
The security firm SlowMist identified the vulnerable FlashLoopAdapter contract and reported that the attacker exploited an access-control flaw in the module used to open and close leveraged Aave v3 positions through Safe wallets. The exploit also enabled the attacker to execute transactions through the victim Safes and drain wETH and collateral.
According to SlowMist, around 1,300 wrapped Ether (wETH) in debt was repaid during the attack to unlock collateral. The attacker ultimately stole about 114.09 Ether (ETH), worth roughly $305,000, from two Safe multisigs.