Aave's V3 Protocol Unscathed by $305K DeFi Exploit
Aave founder Stani Kulechov has confirmed that the lending protocol's v3 version was not affected by a recent exploit that drained $305,000 from two Safe multisig wallets.
The attack targeted a third-party adapter built on top of Aave, which was used to open and close leveraged positions through Safe wallets.
According to Blockchain security firm SlowMist, the attacker exploited an access-control flaw in the adapter's authorization check, allowing a fake Safe contract to pass the check.
The adapter also allowed the attacker to control the router and transaction data used for swaps, enabling them to execute transactions through the victim Safes and drain wETH and collateral.
SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker's wallet, but noted that there were no losses reported to Aave v3 itself.