【Aave Clarifies That the FlashLoopAdapter Vulnerability Belongs to a Third-Party Component, Not the Core Protocol】

Aave founder Stani Kulechov has explicitly clarified that the FlashLoopAdapter vulnerability, which resulted in losses of roughly 114 ETH, exists in a third-party external adapter built on top of Aave, rather than in the Aave v3 core contracts. Aave v3 itself was not affected by this incident.

The previously disclosed attack exploited an access-control vulnerability in this third-party adapter, bypassing permission checks and transferring assets out from two Safes that had enabled this module, leading to an estimated loss of about 114.09 ETH. This clarification is intended to distinguish security issues in third-party integrated components from the security of the underlying protocol.

This incident highlights that third-party adapters or modules built on top of core protocols in the DeFi ecosystem may introduce independent security risks—even if the underlying protocol remains secure. The market should pay attention to auditing and security governance for such integrated components.

Going forward, it will be important to monitor how Aave officially responds regarding the boundaries of security responsibility for third-party components, and whether this vulnerability could affect other Safe multisigs that use similar adapters—thereby assessing its potential impact on the overall reputation of the Aave ecosystem.

$ETH