The situation
Real talk: DeFi is high-key amazing for yield, but this week is a reminder that even when your favorite protocol is solid, the third-party tools you plug into it can be the weak link. Aave founder Stani Kulechov confirmed that Aave v3 is totally fine after a third-party adapter exploit hit two Safe multisig wallets for about $305,000.
How it went down
It’s giving major 'read the fine print' vibes. Security researchers at SlowMist broke down the drama, explaining that the issue wasn’t with Aave’s actual smart contracts. Instead, it was an external module designed to help users open and close leveraged positions through their Safe wallets.
The hacker found an access-control flaw in the 'FlashLoopAdapter' contract. By tricking the adapter with a fake Safe contract, they bypassed the auth checks. From there, they took control of the transaction data, allowing them to repay debt, unlock collateral, and dip with roughly 114 ETH.
Kulechov hopped on X to clarify that this was strictly an external integration issue. No cap, the core Aave v3 protocol remains untouched and fully functional.
Why it matters
This is a classic reminder for all the degens out there: just because you’re using a blue-chip protocol like Aave doesn’t mean every layer built on top of it is audited or safe. Always check your third-party integrations and remember that on-chain security is a shared responsibility. This is not financial advice, but always audit your own risk before connecting your bags to new adapters.





