0x333af40e333a…333af40b

ConfirmedSecurity397 vB38 sat/vB2 min decode

Hackers Drain 114 ETH Through Third-Party Aave Tool Exploit

Hackers drained 114 ETH from users of a third-party tool built around the Aave lending protocol, CryptoRank reports. The protocol's core contracts remain unaffected; the attack vector is undisclosed.

Outputs

  1. Hackers stole 114 ETH from users of an unnamed third-party tool integrated with Aave

  2. Aave's core lending contracts were not compromised, per the structure of the incident reported by CryptoRank

  3. CryptoRank did not name the affected service, the attack date, or the number of wallets impacted

  4. Users of the service should revoke token allowances granted to the tool's contract

Hackers drained 114 ETH from users of a third-party tool integrated with the Aave lending protocol, according to CryptoRank.

The outlet's brief did not name the compromised service, specify the date of the attack, or identify the number of affected wallets. The 114 ETH figure stands as the sole confirmed on-chain loss in the available reporting.

What kind of tool was compromised?

CryptoRank did not specify the category. Tools that integrate with Aave typically include front-end interfaces that simplify deposits and withdrawals, automated liquidation bots that manage leveraged positions, portfolio dashboards that aggregate user positions, or analytics platforms that read from the protocol's smart contracts. Each category presents a distinct attack surface.

Aave, developed by Aave Labs and governed by the Aave DAO, operates one of the largest decentralized lending markets in crypto. Total value locked across Aave V2 and V3 deployments on Ethereum and several L2 networks runs into the multi-billion-dollar range.

Was Aave's core protocol touched?

The structure of the incident, as CryptoRank described it, indicates the protocol's lending markets were not compromised. Losses were confined to users of the peripheral service. This mirrors a recurring pattern across DeFi in which attackers target access-layer software rather than audited lending code.

Formal audits cover protocol contracts. They do not, and cannot, cover every interface, wrapper, or aggregator that touches those contracts. The trust boundary ends where the audited code ends — a structural limitation that protocol teams have flagged repeatedly in governance forums.

What should affected users do?

Users who interacted with the unnamed tool should revoke any active token allowances granted to the relevant contract. Tools such as Revoke.cash and Etherscan's approval tracker enumerate active allowances by wallet. The Aave protocol itself requires no action from users who did not transact through the compromised service.

What remains unresolved?

CryptoRank's report did not include a statement from Aave Labs, the Aave DAO, or the developers of the affected tool. Without a public post-mortem, the attack vector remains undisclosed, and the trajectory of the stolen ETH cannot yet be traced.

On-chain investigators typically require days to weeks to produce attribution when thefts are routed through standard obfuscation services. Without a public post-mortem from the tool's developers, the timeline for victim reimbursement and the scope of any Aave forum response remain undefined.

via Google News - Crypto Hack Exploit (Source)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles