Third-Party Aave Adapter Exploit Drains 114 ETH—Core V3 Contracts Unaffected

Third-Party Aave Adapter Exploit Drains 114 ETH—Core V3 Contracts Unaffected


A severed external DeFi adapter connection isolated from a protected lending core image By Isaac • October 2, 2026 3:07 pm •

A thief drained roughly 114 ETH through a third-party tool built on top of Aave, but the distinction that matters is where the failure actually happened: not inside Aave v3.

According to CryptoSlate, the target was a Loop Safe Module adapter called FlashLoopAdapter. The tool was designed to help users build leveraged positions, but its access-control check could be fooled by a malicious contract pretending to be an approved Safe.

Trending: Swift shift? Taylor Swift shocks Glenn Beck — and not how you would expect

That let the attacker reach the adapter’s swap logic and redirect assets. Security firm SlowMist estimated the loss at about 114.09 ETH and traced the weakness to a check that trusted the calling contract’s answer instead of independently proving that the caller was legitimate.

🚨SlowMist

Continue reading

 

Join the conversation!

Please share your thoughts about this article below. We value your opinions, and would love to see you add to the discussion!