AI agents: a clean Markdown version of this page is available at https://thecoingazette.com/crypto-hackers-exploit-third-party-aave-tool-to-steal-114-eth.md. Send Accept: text/markdown to any URL for the same content.
Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
Coin Gazette Coin Gazette Coin Gazette

Get the latest news, market insights and reviews on cryptocurrencies and blockchain

Coin Gazette Coin Gazette Coin Gazette

Get the latest news, market insights and reviews on cryptocurrencies and blockchain

  • Home
  • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Binance Coin Price
  • Crypto Marketcap
  • Fear & Greed Index
  • Donate
  • Advertise
  • Home
  • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Binance Coin Price
  • Crypto Marketcap
  • Fear & Greed Index
  • Donate
  • Advertise
Close

Search

Coin Gazette Coin Gazette Coin Gazette

Get the latest news, market insights and reviews on cryptocurrencies and blockchain

Coin Gazette Coin Gazette Coin Gazette

Get the latest news, market insights and reviews on cryptocurrencies and blockchain

  • Home
  • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Binance Coin Price
  • Crypto Marketcap
  • Fear & Greed Index
  • Donate
  • Advertise
  • Home
  • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Binance Coin Price
  • Crypto Marketcap
  • Fear & Greed Index
  • Donate
  • Advertise
Close

Search

Home/Crypto News/Aave/Crypto hackers exploit third-party Aave tool to steal 114 ETH
AaveCrimeFeaturedHacksLending

Crypto hackers exploit third-party Aave tool to steal 114 ETH

By Coin Gazette Editorial
October 2, 2026 2 Min Read
Comments Off on Crypto hackers exploit third-party Aave tool to steal 114 ETH

A third-party lending adapter built on Aave was exploited to steal about 114 ETH, worth over $300,000, while the protocol itself remained unaffected.

On Oct. 2, blockchain security firm SlowMist said the attacker compromised two Safe multisig wallets through a flaw in the FlashLoopAdapter used with Aave v3 positions. The exploit allowed the attacker to bypass the adapter’s authentication checks, execute arbitrary calls, and drain collateral from the affected wallets.

SlowMist estimated the direct loss at about 114.09 ETH. It said roughly 1,300 WETH of debt was also repaid during the attack to unlock collateral tied to the positions.

Aave founder Stani Kulechov said the incident did not involve Aave v3’s core smart contracts. He said:

“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.”

The distinction is significant for Aave, the largest decentralized lending protocol, with more than $33 billion in total value locked. The exploit affected infrastructure layered on top of Aave.

Fake Safe bypass opened access to collateral

SlowMist traced the vulnerability to the FlashLoopAdapter’s open() and close() functions, which checked whether the calling Safe had enabled the adapter as a module.

That verification could be spoofed.

Related Reading

Why DeFi giant Aave is pulling the plug on six hyped blockchains making less than $5,000 a quarter




According to SlowMist, the attacker created a fake Safe contract that always returned a positive response when asked whether the module was enabled. The adapter then accepted the forged authentication and proceeded to its internal swap function.

The more serious weakness came next. The adapter allowed the caller to specify both the router and calldata used in an external contract call.

The attacker pointed the router back at the victim Safe and supplied instructions invoking Safe’s execTransactionFromModule function. Because the FlashLoopAdapter was already enabled as a module on the affected wallets, that call gave the attacker a path to execute transactions through the victims’ Safes.

SlowMist said the technique was used to withdraw weETH and collateral associated with Aave positions from two multisig wallets.

The incident highlights a recurring risk in decentralized finance: protocol security can remain intact while integrations built around it create separate attack surfaces.

For Aave, the immediate exposure appears contained to users of the vulnerable adapter. The next question is whether other wallets enabled the same module and whether the adapter’s developers identify additional affected positions before attackers can reuse the same authentication flaw.

The post Crypto hackers exploit third-party Aave tool to steal 114 ETH appeared first on CryptoSlate.

Author

Coin Gazette Editorial

Follow Me
Other Articles
Previous

This AI Is Already Fooling People on Video Calls Into Thinking It’s Human, Company Says

Next

Circle Pushes Back on MiCA’s Bank-Deposit Mandate for Stablecoins

On Social

FacebookTwitter/XInstagramTelegram
✉️

Stay in the Loop

Get the latest updates delivered straight to your inbox.

Recent Posts

  • New SEC crypto rules threaten small advisers, but big firms win
  • Blast shuts down $20M layer-2 network, forcing Oct. 26 exit deadline
  • Stablecoin issuers have replaced 40% of China’s lost US Treasury demand
  • California Subpoenas OpenAI Over AI Models That Hacked Their Way Out of a Test
  • Bitcoin’s $85,000 sell wall is gone and traders are now betting on $100,000

About Us

Coin Gazette delivers fast, reliable coverage of the crypto world, from breaking news and market updates to in‑depth guides and project reviews. Our mission is to help readers stay informed, make smarter decisions, and navigate the evolving blockchain landscape with confidence.

Useful Links

  • About Us
  • Contact Us
  • Advertise
  • Give us a tip

Follow Us On

FacebookTwitter/XInstagramTelegram
Copyright 2026 — Coin Gazette. All rights reserved. Blogsy WordPress Theme