Aave Founder Says v3 Unaffected by $305,000 Third-Party…
By Abdelaziz Fathi

AI summary of the source article
Aave founder Stani Kulechov stated that core v3 contracts were unaffected after an exploit targeting FlashLoopAdapter, a third-party module used by two Safe multisig wallets, resulted in the theft of roughly 114.09 Ether valued at approximately $305,000. Blockchain security firm SlowMist found that the adapter's access controls could be spoofed with a fake Safe contract, permitting unauthorized execution. Although roughly 1,300 WETH was moved to repay debt and release collateral to unwind leveraged positions, the net stolen amount remained around $305,000. The incident highlights integration risks where vulnerabilities exist in third-party modules holding privileged wallet execution rights.
Why it matters
The incident illustrates that DeFi security risks increasingly stem from third-party integrations and modules with privileged access rather than vulnerabilities within the core protocols themselves.
Key facts
- An attacker stole approximately 114.09 Ether ($305,000) by exploiting a third-party Safe module called FlashLoopAdapter.
- Aave founder Stani Kulechov stated that Aave v3 core contracts were unaffected, with system operations remaining normal.
- Roughly 1,300 WETH in debt was repaid during the exploit to unlock collateral before funds were extracted.