Aave V3 Unaffected After Third-Party Adapter Exploit Drains $305K
Key Takeaways
- •An attacker exploited an access-control flaw in the third-party FlashLoopAdapter to steal approximately $305,000, or about 114.09 ETH, from two Safe multisig wallets.
- •Aave founder Stani Kulechov stated the exploit had zero effect on Aave v3 because the compromised adapter was an external tool built on top of the protocol.
- •According to SlowMist, the attacker used a fake Safe contract to pass the adapter's authorization check and controlled the router and swap data to execute transactions through the victims' wallets.
- •Roughly 1,300 wrapped Ether in debt was repaid during the attack to unlock collateral, including weETH, making the underlying assets available for withdrawal.
- •SlowMist identified both the vulnerable contract and the attacker's wallet, which remain traceable on public blockchains, and confirmed no direct losses to Aave v3.

Aave founder Stani Kulechov said the decentralized lending protocol's v3 contracts were unaffected by an exploit that drained roughly $305,000 from two Safe multisig wallets through a third-party adapter built on top of Aave.
"This is not Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3," Kulechov said in a post on X.
Blockchain security firm SlowMist said the attack targeted a module used to open and close leveraged Aave v3 positions through Safe wallets. The attacker exploited an access-control flaw that allowed a fake Safe contract to pass the adapter's authorization check.
Leveraged positioning on lending protocols involves supplying collateral, borrowing against it, and redeploying the borrowed amount to enlarge the position — a cycle that third-party tools automate so users do not have to execute each step manually.
Safe modules are extensions that allow external contracts to execute transactions on behalf of a multisig wallet once the feature is enabled, a design meant to add functionality but one that concentrates risk when authorization checks fail.
According to SlowMist, the adapter also allowed the caller to control the router and the transaction data used for swaps. The attacker used that capability to execute transactions through the victim Safes and drain weETH and other collateral.
Roughly 1,300 wrapped Ether (WETH) in debt was repaid during the attack to unlock the collateral, making the underlying assets accessible for withdrawal. Wrapped Ether is an ERC-20-compliant, tokenized version of Ether that is widely used across decentralized finance applications. The attacker ultimately stole about 114.09 Ether (ETH), worth approximately $305,000, from the two Safe multisigs.
SlowMist identified the vulnerable FlashLoopAdapter contract as well as the attacker's wallet, but reported no losses to Aave v3 itself. Aave's markets are open smart contracts that third-party developers can build on without permission from the protocol, so flaws in surrounding tooling do not by themselves indicate weaknesses in the underlying lending code. Both the FlashLoopAdapter and the attacker's address sit on public blockchains, leaving a visible transaction trail for anyone tracking the stolen funds.
Aave is a decentralized finance lending protocol that lets users supply crypto assets as collateral and borrow against them across multiple blockchains, with protocol decisions governed by holders of its AAVE token. Safe, formerly known as Gnosis Safe, is a widely used multisig wallet platform that requires multiple signatures to approve transactions and is commonly used by decentralized autonomous organizations and treasury managers to secure on-chain funds.