Aave founder Stani Kulechov said the Aave v3 protocol was unaffected by an attack that drained roughly $305,000 from two Safe multisig wallets. The exploit targeted a third-party adapter built on top of Aave, the FlashLoopAdapter, using an access-control flaw that allowed a fake Safe contract to bypass authorization checks. The attacker leveraged this vulnerability to execute transactions and steal weETH and collateral, unlocking approximately 1,300 WETH in debt. In total, around 114.09 ETH, worth roughly $305,000, was stolen from two Safe multisigs, with no losses to Aave v3 itself.
Source: Read the original article

