Swing To Trade
  • Stock
  • Politics
  • Business
  • Investing
Stock

Aave Founder Says v3 Unaffected by $305,000 Third-Party…

by admin October 2, 2026
October 2, 2026

Aave founder Stani Kulechov said the lending protocol’s core v3 contracts were unaffected after an attacker exploited a third-party adapter used by two Safe multisig wallets, ultimately taking about 114.09 Ether worth roughly $305,000.

“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3,” Kulechov said on X.

Blockchain security firm SlowMist traced the incident to FlashLoopAdapter, a module designed to open and close leveraged positions on Aave v3 through Safe wallets. The weakness was in the adapter’s access controls rather than Aave’s lending contracts or Safe’s underlying multisignature architecture.

Aave’s status page showed its systems operating normally, while DefiLlama data put combined Aave total value locked at about $19.4 billion on October 2, making the approximately $305,000 loss small relative to the protocol’s overall deposits but material for the affected wallets.

How Did the FlashLoopAdapter Attack Work?

SlowMist said FlashLoopAdapter’s open() and close() functions checked whether the calling contract reported that the adapter was enabled as a Safe module. The problem was that this response could be spoofed.

The attacker deployed a fake Safe contract that returned a positive result to the authorization check, allowing it to interact with the adapter despite not being an authorized victim wallet. The adapter’s swap function also allowed the caller to specify the router and transaction data, creating another route for attacker-controlled execution.

The attacker then used those permissions to execute transactions through the legitimate Safes, repay debt associated with leveraged Aave positions and withdraw collateral. Security researchers reported that roughly 1,300 WETH in debt was repaid as part of the sequence, unlocking weETH and other collateral.

The architecture is important because enabling a module can give it execution rights that bypass the normal transaction-by-transaction approval flow used by multisig owners. FinanceFeeds examined a similar issue in September when a custom Safe module was used in an attempted $7.7 million rsETH extraction, even though Safe’s core wallet contracts were not compromised.

Investor Takeaway

The security boundary extended beyond Aave v3 and Safe itself. Once a third-party module receives powerful wallet permissions, vulnerabilities in that module can become an alternative path to assets even when the underlying protocols remain secure.

Why Was More Than 1,300 ETH Moved if the Loss Was Only 114 ETH?

The approximately 1,300 WETH figure represents debt repaid during the attack rather than the attacker’s final profit. Repaying the leveraged positions was necessary to release collateral held against the loans.

After the debt repayment, collateral withdrawals and subsequent asset movements were settled, SlowMist estimated the attacker’s net proceeds at about 114.09 ETH, or roughly $305,000 at the time.

That distinction matters in DeFi incident reporting. Large amounts can move through flash loans, collateral repayments and swaps during a single transaction without representing the value ultimately stolen. Using gross transaction flows as the loss figure can materially exaggerate the economic damage.

A similar separation between integration-level losses and core-protocol exposure appeared in another FinanceFeeds report after a $3.2 million Safe exploit linked to an external Squid module. In that incident, the affected integration had been granted wallet authority even though Squid’s core routing infrastructure was not identified as the source of the vulnerability.

Investor Takeaway

The relevant loss figure is the attacker’s net extraction, not every asset that moved while leveraged positions were unwound. Investors assessing DeFi incidents should distinguish collateral movement, debt repayment and flash-loan volume from funds actually lost.

What Does the Exploit Say About DeFi Integration Risk?

The incident adds to evidence that DeFi security increasingly depends on the contracts surrounding major protocols, not only the protocols themselves. Lending markets, smart wallets, automated strategy managers, routers and leverage modules can be composed into a single position, but each additional component adds its own access controls and execution logic.

Safe has been working on transaction-layer defenses through Safenet, which FinanceFeeds covered when the network launched in beta with on-chain transaction security checks. The broader challenge remains that third-party contracts can receive extensive permissions before a vulnerability is discovered.

For Aave, the currently available evidence does not indicate a vulnerability in v3’s core lending pools. The more immediate issue is whether other wallets have enabled the same FlashLoopAdapter and whether the vulnerable contract remains capable of executing privileged transactions against additional Safes.

Investor Takeaway

The next indicators are whether other users were exposed to FlashLoopAdapter, whether affected permissions are revoked, and whether developers publish a full post-mortem or patched implementation. Those developments will determine whether the incident remains limited to two wallets or reveals a wider integration problem.

previous post
Zano Attacker Minted 36.9 Million ZANO and 1.8 Quadrillion…
next post
NEAR Intents Gives Alleged Attacker 48 Hours to Return $3.8…

Related Posts

NEAR Intents Gives Alleged Attacker 48 Hours to...

October 2, 2026

Core Lightning Urges Immediate Upgrade as Attackers Target…

October 2, 2026

Zano Attacker Minted 36.9 Million ZANO and 1.8...

October 2, 2026

Citi Keeps a $2,100 Target on SanDisk After...

October 2, 2026

Bitget Hacker Moves Stolen Zcash Into Private Pool...

October 1, 2026

Micron Reported $14.1 Billion of NAND Sales. SanDisk...

October 1, 2026

Chainalysis Escapes 15 Celsius Claims, but $3.3B Audit...

October 1, 2026

CFTC Wins More Than $30 Million Judgment in...

October 1, 2026

FCA Sets February 2027 Deadline for Crypto Firms...

September 30, 2026

Comer Seeks Crypto.com, Hyperliquid and PredictIt Records…

September 30, 2026
Join The Exclusive Subscription Today And Get Premium Articles For Free

    Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!

    Recent Posts

    • Core Lightning Urges Immediate Upgrade as Attackers Target…

      October 2, 2026
    • NEAR Intents Gives Alleged Attacker 48 Hours to Return $3.8…

      October 2, 2026
    • Aave Founder Says v3 Unaffected by $305,000 Third-Party…

      October 2, 2026
    • Zano Attacker Minted 36.9 Million ZANO and 1.8 Quadrillion…

      October 2, 2026
    • Citi Keeps a $2,100 Target on SanDisk After Micron’s…

      October 2, 2026
    • Privacy Policy
    • Terms & Conditions

    Copyright © 2026 SwingToTrade.com All Rights Reserved.

    Swing To Trade
    • Stock
    • Politics
    • Business
    • Investing