Skip to content
SevenUpdatesNews · 24/7
Crypto

Aave DeFi Exploit: 114 ETH Stolen

Aave DeFi protocol was exploited for 114 ETH due to a vulnerability in a third-party adapter.

💬 𝕏 f in
Aave DeFi protocol logo
Aave DeFi protocol logo

Key Takeaways

  • Aave DeFi protocol was exploited for 114 ETH due to a vulnerability in a third-party adapter.
  • The incident highlights the importance of thorough testing and auditing of third-party integrations.
  • Users must be cautious when interacting with DeFi protocols and carefully review the security of any third-party adapters or modules they use.

Aave DeFi Protocol Exploited for 114 ETH

A third-party lending adapter built on Aave was exploited to steal about 114 ETH, worth over $300,000, while the protocol itself remained unaffected.

On Oct. 2, blockchain security firm SlowMist said the attacker compromised two Safe multisig wallets through a flaw in the FlashLoopAdapter used with Aave v3 positions.

The exploit allowed the attacker to bypass the adapter’s authentication checks, execute arbitrary calls, and drain collateral from the affected wallets.

Incident Details

SlowMist estimated the direct loss at about 114.09 ETH. It said roughly 1,300 WETH of debt was also repaid during the attack to unlock collateral tied to the positions.

Aave founder Stani Kulechov said the incident did not involve Aave v3’s core smart contracts. He said: “This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.”

Vulnerability Explanation

SlowMist traced the vulnerability to the FlashLoopAdapter’s open() and close() functions, which checked whether the calling Safe had enabled the adapter as a module.

According to SlowMist, the attacker created a fake Safe contract that always returned a positive response when asked whether the module was enabled.

The adapter then accepted the forged authentication and proceeded to its internal swap function.

Attack Technique

The more serious weakness came next. The adapter allowed the caller to specify both the router and calldata used in an external contract call.

The attacker pointed the router back at the victim Safe and supplied instructions invoking Safe’s execTransactionFromModule function.

Because the FlashLoopAdapter was already enabled as a module on the affected wallets, that call gave the attacker a path to execute transactions through the victims’ Safes.

  • The attacker used this technique to withdraw weETH and collateral associated with Aave positions from two multisig wallets.
  • The incident highlights a recurring risk in decentralized finance: protocol security can remain intact while integrations built around it create separate attack surfaces.

Impact and Response

For Aave, the immediate exposure appears contained to users of the vulnerable adapter.

The next question is whether other wallets enabled the same module and whether the adapter’s developers identify additional affected positions before attackers can reuse the same authentication flaw.

Aave is +7.55% over the past 24 hours and currently sits at rank #36 by market cap.

Expert Perspective

Experts in the field of DeFi security emphasize the importance of thorough testing and auditing of third-party integrations to prevent such exploits.

The incident also highlights the need for users to be cautious when interacting with DeFi protocols and to carefully review the security of any third-party adapters or modules they use.

Implications for Readers in India

The Aave DeFi exploit serves as a reminder to readers in India of the importance of being aware of the risks associated with DeFi investments.

As the DeFi space continues to grow in popularity, it is essential for investors to educate themselves on the potential risks and take necessary precautions to protect their assets.

What to Watch Next

As the investigation into the Aave DeFi exploit continues, readers can expect to see further updates on the incident and its aftermath.

Additionally, the DeFi community will likely be watching closely to see how Aave and other protocols respond to the incident and implement measures to prevent similar exploits in the future.

Background and Timeline

Aave is a decentralized lending protocol that allows users to borrow and lend cryptocurrencies.

The protocol has gained popularity in recent years due to its decentralized nature and the ability to earn interest on deposited assets.

The incident occurred on October 2, when the attacker exploited the vulnerability in the FlashLoopAdapter.

The attack was detected by SlowMist, which promptly notified Aave and the affected users.

DeFi Security Measures

In light of the incident, DeFi protocols and users must take extra precautions to ensure the security of their assets.

This includes conducting thorough audits and testing of third-party integrations, as well as implementing robust security measures to prevent similar exploits.

Users must also be cautious when interacting with DeFi protocols and carefully review the security of any third-party adapters or modules they use.

Frequently Asked Questions

What is Aave DeFi protocol?

Aave is a decentralized lending protocol that allows users to borrow and lend cryptocurrencies.

What happened in the Aave DeFi exploit?

A third-party lending adapter built on Aave was exploited to steal about 114 ETH, worth over $300,000, while the protocol itself remained unaffected.

What can users do to protect themselves from similar exploits?

Users must be cautious when interacting with DeFi protocols and carefully review the security of any third-party adapters or modules they use.

Share this story WhatsApp X Facebook LinkedIn
24
24SevenUpdates Editorial Desk

Our newsroom tracks India and the world around the clock, turning verified reporting into clear, fast explainers. Read how we source, verify and correct our stories in the editorial policy, or contact the desk about this story.