A third-party adapter exploit drained approximately $305,000 from two Safe multisig wallets, but the underlying Aave v3 protocol remained secure, according to founder Stani Kulechov.
Kulechov clarified on X that the compromised component was an external adapter built on top of Aave, not the v3 contract itself. He emphasised that Aave v3 experienced zero impact from the incident.
Blockchain security firm SlowMist traced the attack to a module designed to manage leveraged Aave v3 positions via Safe wallets. The attacker exploited a flaw in access controls, enabling a counterfeit Safe contract to bypass the adapter's authorisation mechanism.
SlowMist reported that the adapter granted the caller control over both the router and transaction data used in swaps. The attacker leveraged this control to execute unauthorised transactions through victim Safe wallets, withdrawing weETH and other collateral.
During the exploit, the attacker repaid roughly 1,300 wrapped Ether (WETH) in outstanding debt to release locked collateral. SlowMist confirmed the theft totalled around 114.09 Ether (ETH), valued at approximately $305,000, extracted from two Safe multisigs.
The security firm identified both the vulnerable FlashLoopAdapter contract and the wallet address controlled by the attacker. No funds were lost from Aave v3 directly.
Source: cointelegraph.com