Aave founder Stani Kulechov has clarified that the core Aave v3 protocol remained completely unaffected following a security exploit that resulted in the loss of roughly $305,000 from two separate Safe multisig wallets. The incident, which sent ripples through the decentralized finance community, did not target the lending protocol’s native smart contracts, but rather stemmed from an vulnerability within a third-party external adapter built on top of Aave.
The exploit, which primarily targeted specialized modules designed to facilitate advanced financial interactions, quickly drew the attention of industry security experts. As details of the breach began to emerge across social media channels, Kulechov took to the platform X to address community concerns directly and distance the core lending infrastructure from the attack vector.
"This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3," Kulechov stated on X, emphasizing the architectural separation between the core protocol and external integrations that interact with its liquidity pools.
According to a detailed post-incident analysis by blockchain security firm SlowMist, the malicious attack specifically targeted a module utilized for managing leveraged positions. This particular module was designed to allow users to open and close leveraged positions on Aave v3 directly through Safe wallets, a popular institutional-grade multisig custody solution.
The security firm’s investigation revealed that the root cause of the breach was an access-control flaw embedded within the third-party adapter, which was identified as the FlashLoopAdapter contract. Due to this oversight in authorization logic, the attacker was able to successfully pass a fraudulent Safe contract through the adapter’s verification checks, effectively tricking the system into granting unauthorized access.
SlowMist further explained that the compromised adapter possessed design characteristics that granted the caller control over the router and the transaction data utilized for executing token swaps. The perpetrator capitalized on this specific functionality to manipulate transactions flowing through the victimized Safe wallets, ultimately enabling them to systematically drain wrapped Ether and other valuable collateral assets.
During the execution of the exploit, approximately 1,300 wrapped Ether in outstanding debt was strategically repaid to unlock the underlying collateral, as outlined by SlowMist’s on-chain findings. By manipulating the debt positions and clearing the necessary thresholds, the attacker was able to extract approximately 114.09 Ether, which translated to a total monetary loss of roughly $305,000 across the two targeted Safe multisig accounts.
While the incident underscores the ongoing security challenges associated with composable decentralized finance applications and third-party integrations, blockchain security investigators were quick to map out the exact parameters of the event. SlowMist successfully identified both the vulnerable FlashLoopAdapter contract and the specific wallet address controlled by the attacker, providing crucial intelligence to the broader ecosystem. Throughout their comprehensive assessment, the security firm reaffirmed that no direct vulnerabilities, structural compromises, or financial losses were detected within the Aave v3 protocol itself.
