A third-party lending adapter built on Aave was exploited to steal about 114 ETH, worth over $300,000, while the protocol itself remained unaffected.
Crypto hackers exploit third-party Aave tool to steal 114 ETH
A third-party lending adapter built on Aave was exploited to steal about 114 ETH, worth over $300,000, while the protocol itself remained unaffected.
CryptoRank
Publisher
Oct 2, 2026 at 8:35 PM UTC · Updated 2 ngày trước · 2 phút đọc

Key Signal
114.09 ETH Estimated direct loss
Entities
ethereum, aave
Last Updated
2 ngày trước
On Oct. 2, blockchain security firm SlowMist said the attacker compromised two Safe multisig wallets through a flaw in the FlashLoopAdapter used with Aave v3 positions. The exploit allowed the attacker to bypass the adapter’s authentication checks, execute arbitrary calls, and drain collateral from the affected wallets.
SlowMist estimated the direct loss at about 114.09 ETH. It said roughly 1,300 WETH of debt was also repaid during the attack to unlock collateral tied to the positions.
Aave founder Stani Kulechov said the incident did not involve Aave v3’s core smart contracts. He said:
“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.”
The distinction is significant for Aave, the largest decentralized lending protocol, with more than $33 billion in total value locked. The exploit affected infrastructure layered on top of Aave.
Fake Safe bypass opened access to collateral
SlowMist traced the vulnerability to the FlashLoopAdapter’s open() and close() functions, which checked whether the calling Safe had enabled the adapter as a module.
Market Context
Ethereum
ETH
$2,698
+0.61% (24H)
Market Cap
$329.7B
24H Volume
$3.5B
24H High
$2,707
Article Intelligence
Related Coverage
View all relatedSponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
