Aave founder says v3 unaffected after third-party adapter exploit drains $305K
In brief
- Attacker took about 114.09 ETH, roughly $305,000, from two Safe multisigs, SlowMist said.
- FlashLoopAdapter, a third-party adapter built on top of Aave, was the exploited contract.
- Access-control flaw let a fake Safe contract pass the adapter's authorization check, SlowMist said.
- Aave founder Stani Kulechov said on X there was "zero effect on Aave v3."
- Aave v3 itself: SlowMist did not report any losses.
How the adapter was exploited
Kulechov described the contract at the center of the incident as a third-party external adapter built on top of Aave, not an Aave v3 contract. SlowMist said the attack targeted a module used to open and close leveraged Aave v3 positions through Safe wallets.
The flaw came down to access control. According to SlowMist, the attacker got a fake Safe contract past the adapter's authorization check, and the adapter also let the caller control the router and transaction data used for swaps. That's the functionality the attacker used to execute transactions through the victim Safes and drain weETH and collateral.
The numbers are specific. Around 1,300 wrapped Ether (WETH) in debt was repaid during the attack to unlock collateral, SlowMist said, and the attacker ultimately walked away with about 114.09 ETH from the two Safe multisigs.
SlowMist identified the vulnerable contract (FlashLoopAdapter) along with the attacker's wallet.
Kulechov: "zero effect" on Aave v3
Kulechov responded on X, drawing a clear line between the protocol and the adapter that was hit.
“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3,” Kulechov said on X.
That's the founder's own assessment, posted publicly, and it hasn't been independently confirmed in the reporting. SlowMist's findings are consistent with it on one point: the firm didn't report any losses to Aave v3 itself. What it did report was about 114.09 ETH stolen from two Safe multisigs.
SlowMist's tally stands at two wallets and roughly $305,000.
Cointelegraph's report also linked to separate coverage of Aave launching V4 on Avalanche (a different story from this adapter exploit).
Frequently asked questions
Was Aave v3 hacked in the $305,000 exploit?
Aave founder Stani Kulechov said on X that the affected contract wasn't an Aave v3 contract but a third-party external adapter built on top of Aave, with zero effect on Aave v3. SlowMist didn't report any losses to Aave v3 itself.
How did the attacker exploit the FlashLoopAdapter contract?
SlowMist said an access-control flaw let a fake Safe contract pass the adapter's authorization check. The adapter also let the caller control the router and swap transaction data. The attacker used that to execute transactions through the victim Safes and drain weETH and collateral.


