Breaking
CNRussian payment platform A7 is sanctioned by the United States and denies cooperation with IranDERecount in Berlin: AfD candidate Tabor wins direct mandate in SpandauDEThe double blockade: Why politics fails when there is an existential threat to AIRUIn the Ulyanovsk region, school was switched to distance learning due to a bear sightingTR'Trees Opened Books' event was held before Kocaeli Book FairRURussia offered a platform for compromise between Afghanistan and PakistanTRFund Coordination Board met for the second time: Decision to pay investors up to 1 million liraDEArab associations support FIFA President InfantinoITInvestigation by the Palermo Prosecutor's Office: arrests requested for former councilor Gaetano ArmaoCNSatellite images show China constructing proposed full-size runway at Antelope Reef in Paracel IslandsCNRussian payment platform A7 is sanctioned by the United States and denies cooperation with IranDERecount in Berlin: AfD candidate Tabor wins direct mandate in SpandauDEThe double blockade: Why politics fails when there is an existential threat to AIRUIn the Ulyanovsk region, school was switched to distance learning due to a bear sightingTR'Trees Opened Books' event was held before Kocaeli Book FairRURussia offered a platform for compromise between Afghanistan and PakistanTRFund Coordination Board met for the second time: Decision to pay investors up to 1 million liraDEArab associations support FIFA President InfantinoITInvestigation by the Palermo Prosecutor's Office: arrests requested for former councilor Gaetano ArmaoCNSatellite images show China constructing proposed full-size runway at Antelope Reef in Paracel Islands
BackAave v3 Unaffected by $305,000 Exploit Targeting Third-Party Adapter
Aave v3 Unaffected by $305,000 Exploit Targeting Third-Party Adapter
Developing
Cointelegraph49 minutes agoTech1 min read

Aave v3 Unaffected by $305,000 Exploit Targeting Third-Party Adapter

An exploit targeting a third-party adapter drained $305,000 from two Safe multisig wallets, but Aave founder Stani Kulechov confirmed Aave v3 is secure.

Quick Look

  • Aave v3 remained unaffected after an exploit drained roughly $305,000 from two Safe multisig wallets using a third-party adapter.
  • Blockchain security firm SlowMist reported the attack exploited an access-control flaw.

AI-generated summary

Why It Matters

Aave v3 is a decentralized lending protocol. Third-party adapters often build on top of core protocols to offer leveraged positions.

Font size

Aave founder Stani Kulechov said Aave v3 was unaffected by an exploit that drained roughly $305,000 from two Safe multisig wallets through a third-party adapter built on top of the lending protocol.

“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3,” Kulechov said on X.

Blockchain security firm SlowMist said the attack targeted a module used to open and close leveraged Aave v3 positions through Safe wallets. The attacker exploited an access-control flaw that allowed a fake Safe contract to pass the adapter’s authorization check.

SlowMist said the adapter also allowed the caller to control the router and transaction data used for swaps. The attacker used that functionality to execute transactions through the victim Safes and drain weETH and collateral.

Around 1,300 wrapped Ether (WETH) in debt was repaid during the attack to unlock collateral, according to SlowMist. The attacker ultimately stole about 114.09 Ether (ETH), worth roughly $305,000, from two Safe multisigs.

The security firm identified the vulnerable FlashLoopAdapter contract and the attacker’s wallet but did not report any losses to Aave v3 itself.

Open Questions

  • Will the FlashLoopAdapter be permanently patched?
  • Can the stolen funds be recovered?

Related Topics

This article was originally published by Cointelegraph.

Related Stories

Crypto Security Losses Reach $2.7 Billion in 2026, North Korea-Linked Thefts Exceed $1 Billion
Developing·

Crypto Security Losses Reach $2.7 Billion in 2026, North Korea-Linked Thefts Exceed $1 Billion

Crypto firms and users lost nearly $2.7 billion to security incidents in 2026 through September, with North Korea-linked thefts surpassing $1 billion. CertiK recorded 658 incidents, $420.4 million in recovered assets, and September alone accounted for $766.5 million in losses driven by major breaches at Bitget and Liquid Network. The concentration of losses in a few mega-hacks highlights systemic vulnerability, while physical 'wrench attacks' increased significantly in frequency and value.

CryptoSlate
3 min read
More on this topicaave