Crypto hackers exploit third-party Aave tool to steal 114 ETH

요약:Aave founder Stani Kulechov said Aave v3 was unaffected after a third-party adapter exploit drained two multisig wallets.

A third-party lending adapter built on Aave was exploited to steal about 114 ETH, worth over $300,000, while the protocol itself remained unaffected.

Related Asset Aave #36 AAVE · $180.12 24-hour change: up 7.55% Loading price history… 24H Up 7.55% 7D Up 16.28% 30D Up 41.84%

On Oct. 2, blockchain security firm SlowMist said the attacker compromised two Safe multisig wallets through a flaw in the FlashLoopAdapter used with Aave v3 positions. The exploit allowed the attacker to bypass the adapters authentication checks, execute arbitrary calls, and drain collateral from the affected wallets.

SlowMist estimated the direct loss at about 114.09 ETH. It said roughly 1,300 WETH of debt was also repaid during the attack to unlock collateral tied to the positions.

Related Asset Ethereum ETH · $2,670.16 24-hour change: down 1.07%

Aave founder Stani Kulechov said the incident did not involve Aave v3s core smart contracts. He said:

“This is not Aave v3 contract, its third party external adapter built on top of Aave, zero effect on Aave v3.”

The distinction is significant for Aave, the largest decentralized lending protocol, with more than $33 billion in total value locked. The exploit affected infrastructure layered on top of Aave.

Related Person Stani Kulechov Founder and CEO · Aave

Fake Safe bypass opened access to collateral

SlowMist traced the vulnerability to the FlashLoopAdapters open() and close() functions, which checked whether the calling Safe had enabled the adapter as a module.

That verification could be spoofed.

According to SlowMist, the attacker created a fake Safe contract that always returned a positive response when asked whether the module was enabled. The adapter then accepted the forged authentication and proceeded to its internal swap function.

The more serious weakness came next. The adapter allowed the caller to specify both the router and calldata used in an external contract call.

The attacker pointed the router back at the victim Safe and supplied instructions invoking Safe‘s execTransactionFromModule function. Because the FlashLoopAdapter was already enabled as a module on the affected wallets, that call gave the attacker a path to execute transactions through the victims’ Safes.

SlowMist said the technique was used to withdraw weETH and collateral associated with Aave positions from two multisig wallets.

The incident highlights a recurring risk in decentralized finance: protocol security can remain intact while integrations built around it create separate attack surfaces.

For Aave, the immediate exposure appears contained to users of the vulnerable adapter. The next question is whether other wallets enabled the same module and whether the adapters developers identify additional affected positions before attackers can reuse the same authentication flaw.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

미국 2.9만개 일자리 추가…비트코인·금 상승 이유?

다음

Circle, MiCA 검토에서 EU에 스테이블코인 준비금 규정 개정 촉구