Third-Party Adapter Breach Costs Safe Wallets $305,000
An attacker drained approximately $305,000 from two Safe multisig wallets by exploiting a third-party adapter built on Aave v3, though the core lending protocol remained unaffected. Aave founder Stani Kulechov clarified that the compromised component was an external adapter rather than the Aave v3 contract itself, resulting in zero impact to the protocol.
SlowMist identified the attack vector as a module designed for managing leveraged Aave v3 positions through Safe wallets. A flawed authorization check enabled the attacker to present a counterfeit Safe contract that the adapter accepted as legitimate. The adapter's design also granted the caller control over routing and swap transaction data, which the attacker leveraged to execute unauthorized transactions through the compromised Safes.
The attacker repaid roughly 1,300 WETH in outstanding debt to release locked collateral, then extracted approximately 114.09 ETH—valued at around $305,000—from the two multisig wallets. SlowMist traced the vulnerable FlashLoopAdapter contract and the attacker's address, confirming that Aave v3 sustained no direct losses from the incident.
Hot Stories
- Investigations OFAC sanctions 10 for $40M ATM jackpotting using crypto
- Fraud Schemes Fake GIWA bridge steals $2M in Ether from DYORSWAP users
- Articles How Open-Weight AI Helps Hackers Find Code Vulnerabilities
- Investigations iOS app FomoPeek stole $579K in USDT via kernel exploits
- News Bitget confirms $351.6 million hack
- Investigations How AI Is Changing Attacks on Crypto Services
- News Bitget: reports of a possible $170M hack
- Investigations White-hat hackers exploit Liquid Network flaw to steal $320M BTC
- Investigations Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit
- Investigations Blockstream rejects ransom demand after $320M Liquid hack
