Aave founder says V3 unaffected after third-party adapter exploit drains $305K

요약:Aave founder Stani Kulechov said Aave v3 was unaffected after a third-party adapter exploit drained about $305,000 from two Safe multisigs.

Aave founder Stani Kulechov said Aave v3 was unaffected by an exploit that drained roughly $305,000 from two Safe multisig wallets through a third-party adapter built on top of the lending protocol.

“This is not Aave v3 contract, its third party external adapter built on top of Aave, zero effect on Aave v3,” Kulechov said on X.

Blockchain security firm SlowMist said the attack targeted a module used to open and close leveraged Aave v3 positions through Safe wallets. The attacker exploited an access-control flaw that allowed a fake Safe contract to pass the adapters authorization check.

SlowMist said the adapter also allowed the caller to control the router and transaction data used for swaps. The attacker used that functionality to execute transactions through the victim Safes and drain weETH and collateral.

Around 1,300 wrapped Ether (WETH) in debt was repaid during the attack to unlock collateral, according to SlowMist. The attacker ultimately stole about 114.09 Ether (ETH), worth roughly $305,000, from two Safe multisigs.

The security firm identified the vulnerable FlashLoopAdapter contract and the attackers wallet but did not report any losses to Aave v3 itself.

Related: Aave launches V4 on Avalanche, laying groundwork for tokenized credit markets

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

미국 2.9만개 일자리 추가…비트코인·금 상승 이유?

다음

Circle, MiCA 검토에서 EU에 스테이블코인 준비금 규정 개정 촉구