Aave founder says V3 unaffected after third-party adapter exploit drains $305K
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Aave founder Stani Kulechov clarified that Aave v3 itself was not affected by an exploit that resulted in a loss of approximately $305,000 from two Safe multisig wallets. The theft occurred through a third-party adapter built on top of Aave v3, involving an access-control vulnerability in that external module.
Why it matters
The source emphasizes that the exploit did not impact the Aave v3 protocol directly, suggesting the core system remains secure. The incident highlights the risks associated with third-party adapters and integrations layered on top of decentralized finance protocols.
Key context
The attack targeted a module used for managing leveraged Aave v3 positions via Safe wallets. The vulnerability allowed a fake Safe contract to bypass authorization and control transaction parameters, enabling the attacker to drain wrapped Ether (WETH) and collateral from the victim wallets.
Key numbers and entities
The attacker stole about 114.09 ETH, valued at roughly $305,000, from two Safe multisig wallets. The vulnerable contract identified by the security firm SlowMist was the FlashLoopAdapter. Stani Kulechov, founder of Aave, commented on the incident.
What remains unclear
The source does not specify whether any remediation steps have been taken on the third-party adapter or how users of these adapters might be protected moving forward. The identities of the affected multisig wallet owners and any recovery efforts are not reported.