Aave's $33B Vault Held Fine. A Third-Party Adapter Still Leaked 114 ETH
An attacker spoofed an authentication check on FlashLoopAdapter, a third-party tool layered on Aave v3, and drained two Safe multisig wallets of roughly 114 ETH. Aave's core contracts never blinked, which is exactly the problem worth talking about.
Somebody walked off with 114.09 ETH on Oct. 2, and Aave's core contracts had nothing to do with it. The target was FlashLoopAdapter, a third-party lending adapter that sits on top of Aave v3 and helps users loop positions for yield. SlowMist traced the theft to two Safe multisig wallets that had enabled the adapter as a module. Total damage came in north of $300,000.
Here's why the plumbing matters. The adapter's open and close functions asked one question before doing anything: is this Safe's caller authorized? That check was spoofable. An attacker deployed a fake Safe contract that always answered yes, and the adapter believed it.
Then came the real mistake. The adapter let whoever called it specify both the router and the calldata for an external call. So the attacker pointed the router right back at the victim's own Safe and told it to run execTransactionFromModule. Since FlashLoopAdapter was already an approved module, that instruction worked exactly as designed. weETH collateral drained out of both wallets, and roughly 1,300 WETH of debt got repaid mid-attack to unlock the rest.
Aave founder Stani Kulechov pushed back fast on any suggestion the protocol took a hit. "This isn't Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3." He's correct, and the distinction matters. Aave holds more than $33 billion in total value locked. That number didn't move.
But this is the composability tax, and DeFi keeps paying it. Every adapter, wrapper, and helper contract bolted onto a supposedly safe protocol is a new front door, and most of them get a sliver of the audit attention the base layer gets. Think of it this way: you can build the strongest execution layer in the world, and it won't protect you from a poorly written module someone else approved.
For everyday users, nothing changes overnight. Aave positions are fine. Safe module permissions might not be. If you've enabled any third-party module on a multisig, go revoke it today. The attacker never broke Aave. They broke the lazy assumption that anything built on top of it inherits its security, and that assumption is doing a lot of unpaid work across DeFi right now.
Explore More
Key Terms Explained
One of the biggest lending and borrowing protocols in DeFi.
Coinbase's Layer 2 blockchain built on the OP Stack (Optimism's technology).
The data sent along with an Ethereum transaction that tells a smart contract what function to call and with what parameters.
Assets you put up as security when borrowing.