The incident, detected on October 1, centered on a custom contract that acted as an interface between user wallets and the Aave protocol. Security firm SlowMist identified the root cause as a spoofable access control check. The adapter’s open and close functions relied on a check that queried whether a caller was a legitimate Safe module. By deploying a malicious contract that mimicked a verified Safe, the attacker bypassed these security gates to gain unauthorized execution permissions.
Once inside, the attacker orchestrated a complex maneuver using a Morpho flash loan to settle 1,335 WETH of debt held by the primary victim wallet. This repayment unlocked over 1,300 weETH in collateral, which was subsequently withdrawn. A second wallet also suffered minor losses during the incident. After settling the flash loan, the attacker walked away with roughly 114 ETH, valued at $305,000.
Aave founder Stani Kulechov clarified that the exploit was confined to the third-party adapter, emphasizing that the core Aave v3 protocol remained secure and unaffected. This event mirrors previous security lapses involving Safe modules, where external integrations—rather than the primary wallets themselves—served as the point of failure. The vulnerability highlights the risks inherent in delegating transaction execution authority to modular smart contracts, which can effectively grant an attacker the ability to bypass standard owner controls if the authentication logic is flawed.

Comments (0)
No comments yet. Be the first!