FinanceFeedsCrypto

Aave Founder Says v3 Unaffected by $305,000 Third-Party…

By Abdelaziz Fathi

AI summary of the source article

Aave founder Stani Kulechov stated that core v3 contracts were unaffected after an exploit targeting FlashLoopAdapter, a third-party module used by two Safe multisig wallets, resulted in the theft of roughly 114.09 Ether valued at approximately $305,000. Blockchain security firm SlowMist found that the adapter's access controls could be spoofed with a fake Safe contract, permitting unauthorized execution. Although roughly 1,300 WETH was moved to repay debt and release collateral to unwind leveraged positions, the net stolen amount remained around $305,000. The incident highlights integration risks where vulnerabilities exist in third-party modules holding privileged wallet execution rights.

Why it matters

The incident illustrates that DeFi security risks increasingly stem from third-party integrations and modules with privileged access rather than vulnerabilities within the core protocols themselves.

Key facts

  • An attacker stole approximately 114.09 Ether ($305,000) by exploiting a third-party Safe module called FlashLoopAdapter.
  • Aave founder Stani Kulechov stated that Aave v3 core contracts were unaffected, with system operations remaining normal.
  • Roughly 1,300 WETH in debt was repaid during the exploit to unlock collateral before funds were extracted.