An attacker drained roughly $305,000 from two Safe multisig wallets by exploiting a third-party adapter built on Aave v3. Aave founder Stani Kulechov said the protocol's core contracts were unaffected, and security firm SlowMist traced the breach to an access-control flaw in the adapter.
An attacker drained roughly $305,000 from two Safe multisig wallets by exploiting a third-party adapter built on top of Aave v3. Aave founder Stani Kulechov said the protocol's own contracts came through untouched.
Kulechov wrote on X that the adapter was built on top of Aave, calling it “zero effect on Aave v3”. Blockchain security firm SlowMist traced the exploit to a module used to open and close leveraged Aave v3 positions through Safe wallets.
SlowMist said an access-control flaw let a fake Safe contract pass the adapter's authorization check, and that the adapter also let the caller control the router and transaction data used for swaps. The attacker then used that access to execute transactions through the victim Safes and drain weETH and collateral, the firm said.
The attacker repaid about 1,300 wrapped Ether (WETH) in debt to unlock collateral. The attacker then withdrew roughly 114.09 Ether (ETH), worth about $305,000, from the two Safes. SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker's wallet but reported no losses to Aave v3 itself.
Source: Cointelegraph
Trading involves risk.