• Terms and conditions
  • Privacy Policy
Friday, October 2, 2026
Informed American Today
No Result
View All Result
  • Politics
  • Business
  • Economy
  • Stock Market
  • Editor’s Choice
  • Politics
  • Business
  • Economy
  • Stock Market
  • Editor’s Choice
No Result
View All Result
Morning News
No Result
View All Result
Home Editor's Pick

Aave Founder Says v3 Unaffected by $305,000 Third-Party…

informedamericantoday by informedamericantoday
October 2, 2026
in Editor's Pick
0
Aave Founder Says v3 Unaffected by $305,000 Third-Party…

Aave founder Stani Kulechov said the lending protocol’s core v3 contracts were unaffected after an attacker exploited a third-party adapter used by two Safe multisig wallets, ultimately taking about 114.09 Ether worth roughly $305,000.

“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3,” Kulechov said on X.

Blockchain security firm SlowMist traced the incident to FlashLoopAdapter, a module designed to open and close leveraged positions on Aave v3 through Safe wallets. The weakness was in the adapter’s access controls rather than Aave’s lending contracts or Safe’s underlying multisignature architecture.

READ ALSO

Core Lightning Urges Immediate Upgrade as Attackers Target…

NEAR Intents Gives Alleged Attacker 48 Hours to Return $3.8…

Aave’s status page showed its systems operating normally, while DefiLlama data put combined Aave total value locked at about $19.4 billion on October 2, making the approximately $305,000 loss small relative to the protocol’s overall deposits but material for the affected wallets.

How Did the FlashLoopAdapter Attack Work?

SlowMist said FlashLoopAdapter’s open() and close() functions checked whether the calling contract reported that the adapter was enabled as a Safe module. The problem was that this response could be spoofed.

The attacker deployed a fake Safe contract that returned a positive result to the authorization check, allowing it to interact with the adapter despite not being an authorized victim wallet. The adapter’s swap function also allowed the caller to specify the router and transaction data, creating another route for attacker-controlled execution.

The attacker then used those permissions to execute transactions through the legitimate Safes, repay debt associated with leveraged Aave positions and withdraw collateral. Security researchers reported that roughly 1,300 WETH in debt was repaid as part of the sequence, unlocking weETH and other collateral.

The architecture is important because enabling a module can give it execution rights that bypass the normal transaction-by-transaction approval flow used by multisig owners. FinanceFeeds examined a similar issue in September when a custom Safe module was used in an attempted $7.7 million rsETH extraction, even though Safe’s core wallet contracts were not compromised.

Investor Takeaway

The security boundary extended beyond Aave v3 and Safe itself. Once a third-party module receives powerful wallet permissions, vulnerabilities in that module can become an alternative path to assets even when the underlying protocols remain secure.

Why Was More Than 1,300 ETH Moved if the Loss Was Only 114 ETH?

The approximately 1,300 WETH figure represents debt repaid during the attack rather than the attacker’s final profit. Repaying the leveraged positions was necessary to release collateral held against the loans.

After the debt repayment, collateral withdrawals and subsequent asset movements were settled, SlowMist estimated the attacker’s net proceeds at about 114.09 ETH, or roughly $305,000 at the time.

That distinction matters in DeFi incident reporting. Large amounts can move through flash loans, collateral repayments and swaps during a single transaction without representing the value ultimately stolen. Using gross transaction flows as the loss figure can materially exaggerate the economic damage.

A similar separation between integration-level losses and core-protocol exposure appeared in another FinanceFeeds report after a $3.2 million Safe exploit linked to an external Squid module. In that incident, the affected integration had been granted wallet authority even though Squid’s core routing infrastructure was not identified as the source of the vulnerability.

Investor Takeaway

The relevant loss figure is the attacker’s net extraction, not every asset that moved while leveraged positions were unwound. Investors assessing DeFi incidents should distinguish collateral movement, debt repayment and flash-loan volume from funds actually lost.

What Does the Exploit Say About DeFi Integration Risk?

The incident adds to evidence that DeFi security increasingly depends on the contracts surrounding major protocols, not only the protocols themselves. Lending markets, smart wallets, automated strategy managers, routers and leverage modules can be composed into a single position, but each additional component adds its own access controls and execution logic.

Safe has been working on transaction-layer defenses through Safenet, which FinanceFeeds covered when the network launched in beta with on-chain transaction security checks. The broader challenge remains that third-party contracts can receive extensive permissions before a vulnerability is discovered.

For Aave, the currently available evidence does not indicate a vulnerability in v3’s core lending pools. The more immediate issue is whether other wallets have enabled the same FlashLoopAdapter and whether the vulnerable contract remains capable of executing privileged transactions against additional Safes.

Investor Takeaway

The next indicators are whether other users were exposed to FlashLoopAdapter, whether affected permissions are revoked, and whether developers publish a full post-mortem or patched implementation. Those developments will determine whether the incident remains limited to two wallets or reveals a wider integration problem.

Related Posts

Core Lightning Urges Immediate Upgrade as Attackers Target…
Editor's Pick

Core Lightning Urges Immediate Upgrade as Attackers Target…

October 2, 2026
NEAR Intents Gives Alleged Attacker 48 Hours to Return $3.8…
Editor's Pick

NEAR Intents Gives Alleged Attacker 48 Hours to Return $3.8…

October 2, 2026
Citi Keeps a $2,100 Target on SanDisk After Micron’s…
Editor's Pick

Citi Keeps a $2,100 Target on SanDisk After Micron’s…

October 2, 2026
Zano Attacker Minted 36.9 Million ZANO and 1.8 Quadrillion…
Editor's Pick

Zano Attacker Minted 36.9 Million ZANO and 1.8 Quadrillion…

October 2, 2026
Bitget Hacker Moves Stolen Zcash Into Private Pool — About…
Editor's Pick

Bitget Hacker Moves Stolen Zcash Into Private Pool — About…

October 1, 2026
Micron Reported $14.1 Billion of NAND Sales. SanDisk Jumped…
Editor's Pick

Micron Reported $14.1 Billion of NAND Sales. SanDisk Jumped…

October 1, 2026
Next Post
Core Lightning Urges Immediate Upgrade as Attackers Target…

Core Lightning Urges Immediate Upgrade as Attackers Target…

    Become a VIP member by signing up for our newsletter. Enjoy exclusive content, early access to sales, and special offers just for you! As a VIP, you'll receive personalized updates, loyalty rewards, and invitations to private events. Elevate your experience and join our exclusive community today!

    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Disclaimer: InformedAmericanToday.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    Categories

    • Business
    • Economy
    • Editor's Pick
    • Politics
    • Stock Market

    Recent Posts

    • Core Lightning Urges Immediate Upgrade as Attackers Target…
    • NEAR Intents Gives Alleged Attacker 48 Hours to Return $3.8…
    • Aave Founder Says v3 Unaffected by $305,000 Third-Party…
    • Zano Attacker Minted 36.9 Million ZANO and 1.8 Quadrillion…
    • Terms and conditions
    • Privacy Policy

    Copyright © 2026 informedamericantoday.com | All Rights Reserved

    No Result
    View All Result
    • Politics
    • Business
    • Economy
    • Stock Market
    • Editor’s Choice

    Copyright © 2026 informedamericantoday.com | All Rights Reserved

    No Result
    View All Result
    • Politics
    • Business
    • Economy
    • Stock Market
    • Editor’s Choice

    Copyright © 2026 informedamericantoday.com | All Rights Reserved