Aave founder says V3 unaffected after third-party adapter exploit drains $305K

Lời nói đầu:Aave founder Stani Kulechov said Aave v3 was unaffected after a third-party adapter exploit drained about $305,000 from two Safe multisigs.

Aave founder Stani Kulechov said Aave v3 was unaffected by an exploit that drained roughly $305,000 from two Safe multisig wallets through a third-party adapter built on top of the lending protocol.

“This is not Aave v3 contract, its third party external adapter built on top of Aave, zero effect on Aave v3,” Kulechov said on X.

Blockchain security firm SlowMist said the attack targeted a module used to open and close leveraged Aave v3 positions through Safe wallets. The attacker exploited an access-control flaw that allowed a fake Safe contract to pass the adapters authorization check.

SlowMist said the adapter also allowed the caller to control the router and transaction data used for swaps. The attacker used that functionality to execute transactions through the victim Safes and drain weETH and collateral.

Around 1,300 wrapped Ether (WETH) in debt was repaid during the attack to unlock collateral, according to SlowMist. The attacker ultimately stole about 114.09 Ether (ETH), worth roughly $305,000, from two Safe multisigs.

The security firm identified the vulnerable FlashLoopAdapter contract and the attackers wallet but did not report any losses to Aave v3 itself.

Related: Aave launches V4 on Avalanche, laying groundwork for tokenized credit markets

Miễn trừ trách nhiệm

Các ý kiến ​​trong bài viết này chỉ thể hiện quan điểm cá nhân của tác giả và không phải lời khuyên đầu tư. Thông tin trong bài viết mang tính tham khảo và không đảm bảo tính chính xác tuyệt đối. Nền tảng không chịu trách nhiệm cho bất kỳ quyết định đầu tư nào được đưa ra dựa trên nội dung này.
Bài viết trước

Cổ phiếu Tesla tăng 6% nhờ kết quả giao hàng vượt dự báo: Lợi nhuận có hỗ trợ cho mức tăng này không?