Aave founder Stani Kulechov stated that Aave v3 was not affected after an attacker used a third-party adapter operating on top of the protocol to withdraw about $305,000 from two Safe multisig wallets.

Exploit Targeted Module for Leveraged Position Management

According to blockchain analysts, the attack targeted a module used for opening and closing leveraged positions in Aave v3 through Safe wallets. The attacker exploited a flaw in access control, allowing a "fake" Safe contract to pass the adapter's authorization check.

Access to Router and Data Enabled Withdrawal of weETH and Collateral

The adapter gave the caller control over the router and transaction data for swaps. The attacker used this functionality to execute operations on behalf of the targeted Safe wallets and withdraw weETH and collateral assets.

FlashLoopAdapter Identified; 114.09 ETH Stolen

During the attack, about 1,300 WETH in debt was repaid to unlock collateral. In total, the attacker withdrew approximately 114.09 ETH (about $305,000) from two Safe multisigs. The vulnerable FlashLoopAdapter contract and the attacker's address have been identified; no losses were recorded for Aave v3.