At first glance, it’s just another small DeFi theft case: $300,000 sitting in today’s crypto market doesn’t even qualify as news. But what’s truly worth looking at is where that knife went in..

🏛️ 今日盘面群里聊

Most people see it as “Aave was attacked again.” But the founder came out with a very straightforward statement: it wasn’t the Aave v3 contract that had the problem—it was a third-party adapter layer built on top of it, with zero impact on the main protocol.

Specifically, the module named is called FlashLoopAdapter. Its job is to help users open and close leveraged positions on Aave via a Safe multi-signature wallet. The vulnerability lies in the permission-checking step: the attacker constructed a fake Safe contract that bypassed the adapter’s authorization checks. Even more troubling, it also lets the caller specify the swap router and transaction data themselves.

So the attacker used the victim’s Safe to execute the transactions, pulling out the weETH and the collateral. During the process, they also repaid roughly 1,300 WETH debts on the victims’ behalf to unlock the collateral. Finally, they took about 114 ETH—worth approximately $305,000—from two Safe wallets.

Zoom out: the key point isn’t really the $300,000. It’s that the risk is shifting outward. The more mature the protocol core is and the thicker the audits are, the more attackers move their focus toward the “periphery”—those adapters, wrappers, and aggregators that grew out of the system to make it more usable. They extend the protocol’s reach further and widen the attack surface.

In the funding layer, reactions to this kind of event are more honest than the price. When large capital evaluates a lending protocol, it’s not just about TVL and interest rates—it also looks at the worst-case loss limit: when things go wrong, can the losses be confined to a small module and avoid contaminating the main liquidity pool? In this case, Aave v3 held up, giving the main pool’s money even more reason to stay. Conversely, if one day the leak is the main pool itself, the story would go in an entirely different direction..

A twist to end on: what really should be watched isn’t the $300,000 stolen this time—it’s when these kinds of external adapters can have a unified set of permission and audit standards. As long as they continue to grow in an untamed way, a single oversight in permission validation is enough to turn into a trust discount for the entire ecosystem from large capital.