WiremarketsPublisher preview

Crypto hackers exploit third-party Aave tool to steal 114 ETH

A third-party lending adapter built on Aave was exploited to steal about 114 ETH, worth over $300,000, while the protocol itself remained unaffected. On Oct. 2, blockchain security firm SlowMist said the attacker compromised two Safe multisig wallets through a flaw in the FlashLoopAdapter used with Aave v3 positions.

Assets in this piece

CoinGecko last prints — not a Dextape quote.

Key points

  • SlowMist said an attacker exploited a FlashLoopAdapter flaw to compromise two Safe multisig wallets, stealing about 114.09 ETH, worth over $300,000, on Oct. 2.
  • According to SlowMist, a fake Safe contract spoofed module authentication, letting the attacker supply arbitrary router calldata and drain weETH and Aave-linked collateral.
  • Aave founder Stani Kulechov said Aave v3's core contracts were unaffected, describing the exploited code as a third-party external adapter built on top of Aave.

AI summary of CryptoSlate’s report, written only from the publisher’s text. Read the original for full context.

Read the full story

Headline and excerpt from CryptoSlate’s public feed. CryptoSlate holds the copyright and publishes the full story; Dextape links to it rather than reprinting it.

Related Dextape