0x7b3a3eb77b3a…7b3a3eba
Aave v3 Unaffected After Third-Party Adapter Exploit Drains $305K
Aave founder Stani Kulechov said the protocol's v3 contracts remain untouched after an attacker exploited a third-party adapter to drain roughly $305,000 from two Safe multisigs.
Outputs
Roughly $305,000 (114.09 ETH) drained from two Safe multisig wallets on March exploit
Aave v3 contracts unaffected, founder Stani Kulechov confirmed on X
SlowMist identified an access-control flaw in a FlashLoopAdapter contract
Around 1,300 WETH of debt was repaid during the attack to unlock collateral
The exploit path ran through a third-party adapter rather than Aave's core lending markets
Aave v3 contracts remain untouched after an attacker drained roughly $305,000 from two Safe multisig wallets through a third-party adapter built on top of the lending protocol, founder Stani Kulechov said on X.
"This is not Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3," Kulechov wrote, distancing the core protocol from the loss.
The attack targeted a module used to open and close leveraged Aave v3 positions through Safe wallets, according to blockchain security firm SlowMist. SlowMist traced the incident to a vulnerability in a contract it identified as FlashLoopAdapter.
What did the attacker actually exploit?
SlowMist's post-mortem described an access-control flaw that permitted a fake Safe contract to pass the adapter's authorization check. Once through that gate, the adapter also allowed the caller to control the router and the transaction data used for swaps.
That combination let the attacker execute transactions through the victim Safes and siphon weETH alongside other collateral held inside the wallets.
How much was lost?
During the attack, roughly 1,300 wrapped Ether (WETH) of debt was repaid to unlock the underlying collateral, per SlowMist. The attacker ultimately extracted about 114.09 Ether (ETH), valued at approximately $305,000, from the two Safe multisigs.
Could Aave v3 depositors be affected?
Kulechov's framing was categorical. He insisted the affected contract sat outside Aave v3. SlowMist separately confirmed it located the vulnerable contract and the attacker's wallet, but reported no losses to Aave v3 itself.
The exploit path ran entirely through the external adapter layer rather than through Aave's core lending markets, where user deposits back loans and collateralization ratios.
What's the operational fallout?
The incident adds to a string of adapter-level compromises across DeFi, where composable wrappers sit atop core contracts but inherit exposure to weaker access controls. Flash-loan wrappers, leveraged position managers and cross-chain bridges have each produced comparable losses in recent memory.
Aave Labs has not announced a remediation timeline for users of the third-party adapter. The operator of FlashLoopAdapter has not been publicly identified in SlowMist's write-up. Safe itself, the multisig standard used by the victims, was not implicated.
For institutional desks weighing exposure to Aave, the distinction between core protocol risk and integration-layer risk is increasingly material during due diligence. Audits of named wrappers now sit alongside audits of the underlying lending markets on standard checklists.
What does this mean for DeFi risk models?
The exploit sharpens a long-running critique from institutional risk teams: protocol-level safety guarantees stop at the boundary of third-party integrations. For Aave, the public implication is straightforward — the v3 brand emerges intact — but the technical record now carries another entry in the category of wrapper-mediated drains that compliance officers flag during onboarding.
SlowMist's identification of the attacker wallet creates a basis for on-chain tracing. Recovery of the 114.09 ETH depends on the operational response of the adapter's maintainers and the cooperation of the venues through which the funds were subsequently routed. Aave's wider roadmap, including its v4 deployment on Avalanche for tokenized credit markets, proceeds separately from the incident and was not referenced in Kulechov's response.
via x.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
439 articles