Aave founder says V3 unaffected after third-party adapter exploit drains $305K

Aave founder Stani Kulechov said Aave v3 contracts were not impacted after an attacker exploited a third-party adapter and drained about $305,000 from two Safe multisig wallets. Blockchain security firm SlowMist reported the attacker abused an access-control flaw in a FlashLoopAdapter used to open and close leveraged Aave v3 positions via Safe wallets, allowing unauthorized transactions that seized roughly 114.09 ETH.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 2 hours agoUpdated about 2 hours ago0 views
Aave founder says V3 unaffected after third-party adapter exploit drains $305K

Why It Matters

The incident highlights risks introduced by external integrations built on top of core DeFi protocols, even when the base protocol remains secure. It underscores the importance of auditing and securing adapters and modules that bridge multisig wallets and lending platforms.

Key Facts

  • Affected protocol: Third-party adapter built on Aave v3 (not Aave v3 contracts themselves)
  • Amount stolen: Approximately 114.09 ETH (~$305,000)
  • Targeted wallets: Two Safe multisig wallets
  • Vulnerability: Access-control flaw allowing a fake Safe contract to pass adapter authorization
  • Adapter identified: FlashLoopAdapter

Aave founder Stani Kulechov said Aave v3 itself was not compromised after an attacker exploited a third-party adapter layered on top of the lending protocol to drain funds from two Safe multisig wallets. Kulechov posted that the issue involved an external adapter rather than any Aave v3 contract, indicating zero effect on the core protocol.

Security firm SlowMist provided technical details of the breach, saying the attacker targeted a module used to open and close leveraged Aave v3 positions through Safe wallets. According to SlowMist, an access-control weakness in the adapter allowed a fake Safe contract to satisfy the adapter’s authorization checks, giving the attacker the ability to control router and transaction data for swaps.

SlowMist said the attacker leveraged that control to execute transactions through the victim Safes, repaying around 1,300 wrapped Ether (WETH) in debt to unlock collateral and ultimately seizing about 114.09 ETH, valued at roughly $305,000, from the two multisig wallets. The firm named the vulnerable contract as FlashLoopAdapter and disclosed the attacker’s wallet but did not report any direct losses to Aave v3 itself.

The episode illustrates how vulnerabilities in composable DeFi components—such as adapters that connect multisig wallets to lending protocols—can produce material losses even when the underlying protocol remains secure. It reinforces industry calls for thorough audits and careful access-control design in integrations that mediate actions on behalf of multisigs and other custodial arrangements.

Keep Reading