By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Aave V3 Unaffected by Third-Party Adapter Exploit

Aave founder Stani Kulechov announced on X (formerly Twitter) that the Aave v3 protocol was not impacted by a recent exploit targeting a third-party adapter. The incident resulted in the draining of approximately $305,000 from two Safe multisig wallets. Kulechov clarified that the exploit did not compromise the Aave v3 smart contracts themselves, emphasizing the protocol's security and resilience. The funds were reportedly stolen from wallets managed by the decentralized finance (DeFi) platform GMX, which utilized the compromised adapter. This distinction is crucial, as it highlights a vulnerability in an external integration rather than the core Aave protocol. The exploit occurred on June 20, 2024, according to blockchain security firm PeckShield, which reported the incident and the amount stolen. The stolen funds were transferred to an address controlled by the attacker. Safe multisig wallets are a security feature designed to require multiple approvals for transactions, adding an extra layer of protection against unauthorized access. The fact that these wallets were compromised suggests a sophisticated attack that may have bypassed or exploited the multisignature mechanism through the third-party adapter. GMX, a decentralized perpetual exchange, confirmed that the exploit affected its treasury and that it was working with security partners to investigate the incident. The company stated that it was taking steps to secure its remaining assets and would provide further updates. The incident underscores the inherent risks associated with third-party integrations in the DeFi ecosystem, where the security of one component can have cascading effects on others. While Aave v3 itself was not directly breached, the event serves as a reminder of the interconnectedness of DeFi protocols and the importance of rigorous security audits for all integrated services. Kulechov's swift clarification aimed to reassure Aave users and the broader DeFi community about the integrity of the Aave v3 protocol. The DeFi space has seen a rise in exploits and hacks, with billions of dollars lost annually. These incidents often target smart contract vulnerabilities, flash loan attacks, or, as in this case, vulnerabilities in auxiliary services and integrations. The total amount stolen, $305,000, while significant, is considerably less than many other high-profile DeFi hacks, but it still represents a substantial loss for the affected parties. The investigation into the specific nature of the third-party adapter's vulnerability is ongoing, with security researchers working to identify the exact method used by the attacker to gain control of the multisig wallets. The incident is likely to prompt further scrutiny of third-party integrations and smart contract auditing practices within the DeFi industry.
Original source — read the full reporting at the publisher:
Read on CoinTelegraphGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.