Aave founder says V3 unaffected after third-party adapter exploit drains $305K

Summary

Aave v3 itself was not exploited. Stani Kulechov said the loss came from a third-party adapter built on top of Aave, with zero impact on core Aave v3 contracts. SlowMist said the attack targeted a leveraged-position module used with Safe multisig wallets. A flaw in access control let a fake Safe contract pass authorization, and the adapter also let the attacker control router and swap transaction data. Using this, the attacker executed transactions through two victim Safes, repaid about 1,300 WETH in debt to unlock collateral, and drained roughly 114.09 ETH, or about $305,000.