• 4 mins read
  • Published

Aave adapter hack exposes DeFi integration flaws as 114 ETH stolen

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Aave adapter hack exposes DeFi integration flaws as 114 ETH stolen EgonCoin © egoncoin.com
Aave adapter hack exposes DeFi integration flaws as 114 ETH stolen © egoncoin.com

Hackers stole over $300,000 in ETH by exploiting a flaw in a third-party adapter built on Aave v3. The theft raises new questions about the risks of DeFi integrations beyond the main protocol code.

Hackers found a way into a third-party adapter built on Aave v3 and stole about 114 ETH, worth more than $300,000. They took advantage of a weakness in how the adapter checked who was allowed to use it. Aave's main smart contracts were not touched. But the attack shows how tools built on top of big DeFi protocols can open up new ways for thieves to get at user funds.

How the adapter was hacked

The attack focused on the FlashLoopAdapter, a tool meant to work with Aave v3 lending positions. Blockchain security firm SlowMist explained that the hacker got around the adapter's checks by making a fake Safe multisig contract. This fake contract was set up to always say "yes" when asked about module permissions. That tricked the adapter into accepting fake credentials. Once inside, the hacker could make the adapter run any contract call they wanted. In the end, they drained collateral from two multisig wallets.

The exploit resulted in losses of approximately 114.09 ETH (about $305,000), affecting two Safe multisig wallets but leaving Aave v3 core contracts untouched.

Cointelegraph

The hacker used the exploit to pay back about 1,300 WETH of debt. That let them unlock collateral, which they then withdrew. The root of the problem was in the adapter's open and close functions. These functions did not properly check if the Safe contract calling them was real. By setting the router parameter to point back at the victim wallet and using Safe's execTransactionFromModule function, the hacker could run unauthorized transactions through the compromised wallets.

Damage limited to external integration

Aave founder Stani Kulechov said the protocol's main contracts were not involved. The hack only hit the external adapter. This matters for Aave, which is still the biggest decentralized lending protocol with over $33 billion locked up. The main Aave v3 contracts and user funds inside the protocol were safe. The attack only hit infrastructure built on top of Aave.

For now, the risk seems limited to users who turned on the vulnerable adapter module in their Safe wallets. But there's a bigger worry: other wallets or integrations might have the same problem. The adapter's developers now have to find and secure any other wallets at risk before more attacks happen. As reported earlier, even strong protocols can face new threats when outside tools or integrations are added.

The vulnerability was rooted in the adapter's access-control logic, where attacker-controlled router and calldata parameters enabled arbitrary calls via compromised Safe wallets. This highlights the importance of rigorous security reviews for all DeFi integrations, not just core protocol code.

TechFlowPost

Security lessons for DeFi users

This hack shows how complicated DeFi security has become. Keeping user funds safe depends not just on the main protocol code, but also on third-party tools, adapters, and wallet modules. Hackers are now going after these integration points, looking for weak spots in authentication, permissions, or contract logic that the main protocol might not have. For both developers and users, this is a warning: check the security of every part of the stack, not just the main protocol.

SlowMist said the direct loss was about 114.09 ETH. The hacker paid back a large amount of WETH debt to unlock and take out collateral. The breach was made public on October 2. At the time, the damage seemed limited to the multisig wallets using the compromised adapter.

Aave still has more than $33 billion locked in its protocol. But because the ecosystem is layered, a weakness in an outside integration can still hurt users. This adapter hack is a clear example of how DeFi's composability-a key feature-can also make things riskier when security breaks down at the edges.

DeFi is often praised for letting developers build new tools and user experiences quickly. But every extra layer-like a wallet module, adapter, or automation tool-can give hackers a new way in. In traditional finance, security boundaries are tightly controlled. In DeFi, the open design means a flaw in one part can spread across protocols and user funds. For users, this means you need to check the safety of every tool and contract you use-not just the main protocol. For developers, it's vital to run tough security reviews and keep an eye on integrations to protect assets and keep trust in a fast-changing ecosystem.

Related articles