114 ETH stolen, headlines say Aave was hacked — Aave founder directly deflects blame: it’s not an Aave problem!

What happened: the hacker didn’t target Aave’s main contract, but a third-party module called FlashLoopAdapter. This module helps users perform leveraged looping on Aave v3 (supply → borrow → supply again, amplifying exposure). However, the module had a fatal permission-check flaw: the attacker used a fake Safe contract to bypass identity verification, effectively obtaining a master key to the treasury. Then, they took out a flash loan from Morpho to repay about 1335 WETH of debt and unlocked the collateral. Finally, they withdrew around 1306 weETH from two Safe wallets, ending with a net profit of 114.09 ETH (about $305,000).
Aave founder Stani Kulechov immediately stated on X: this is a third-party external adapter built on top of Aave; Aave v3 itself has zero impact.

My take: this incident clearly shows that the biggest risk in DeFi often isn’t in the protocol itself, but in the “Lego” components around it. You might never have heard of FlashLoopAdapter, but as long as you authorize this module to your Safe wallet, it can move your money — that’s the devilish detail of module permissions. Recently, more and more on-chain attacks have been taking the “borrow someone else’s knife” route: directly biting into Aave or Uniswap is too hard, so attackers go after third-party components in their ecosystems that have weaker audits.
How can regular users protect themselves? Two practical ways: first, regularly check the Safe’s module list; disable any module you don’t recognize (in this case, the two Safes stolen were owned by the same person, and were disabled only after the theft). Second, don’t keep large amounts of funds long-term in a wallet that’s running leveraged looping — the extra few percentage points in yield may cost you your principal. 114 ETH isn’t a huge amount, but the method is worth every on-chain participant remembering.

Data as of: 2026-10-02 15:00 UTC
Sources: SlowMist; Cointelegraph
For information sharing only and does not constitute investment advice.

$AAVE $ETH

Do you regularly check the modules authorized by your wallet? Let’s discuss in the comments.
I’ll keep following these types of security incidents—stay with me so you don’t get lost.