Aave founder Stani Kulechov confirmed that the core Aave v3 protocol was unaffected by an exploit that resulted in the loss of roughly $305,000. The incident involved a third-party external adapter built on top of the lending protocol, specifically targeting two Safe multisig wallets. Kulechov clarified on X that the vulnerability did not reside within the Aave v3 contract itself but rather in the external module used to manage leveraged positions.

Blockchain security firm SlowMist identified the attack vector as an access-control flaw in the FlashLoopAdapter contract. This flaw allowed a fake Safe contract to bypass authorization checks and enabled the attacker to control router and transaction data for swaps. By exploiting this functionality, the attacker executed transactions through the victim Safes, repaying around 1,300 wrapped Ether (WETH) in debt to unlock collateral before stealing about 114.09 Ether (ETH). SlowMist noted no losses were incurred by Aave v3 directly, isolating the breach to the third-party infrastructure.