The hacker struck again.

This time, the target was a third-party tool built on Aave.

After investigation: the problem was with a plugin tool whose access control was fake. The hacker brazenly entered two wallets and took the collateral funds.

114 ETH, hundreds of thousands of dollars, gone.

What about Aave?

Nothing happened.

People were somewhat relieved: luckily, the main platform is fine.

Relieved about what?

"The main platform is fine" means:

The money is gone, but it’s not my problem.

Issue a statement, draw a line, and that’s it.

No one compensates you, no one covers your loss.

If you lose money in a bank, at least there’s some accountability.

Now, whether there is or isn’t, it’s up for debate, haha.

Lose money on Aave?

You might get a tweet.

It gets worse.

They have hundreds of billions locked inside, always topping the charts.

But those numbers show their strength, not your security.

The most infuriating thing is, once something happens, someone says:

Who told you not to read the code yourself?

When you fly, do you have to know how to fix the engine?

When you deposit in a bank, do you have to understand risk control?

But on Aave, if you lose money, first blame yourself for not reading the code.

On one hand, they shout for everyone to come,

on the other, they demand everyone to be able to read code.

That’s just shirking responsibility.

So the real headline here isn’t that the hacker stole hundreds of thousands.

It’s that money was lost and no one takes responsibility.

One last question.

Do you still dare to put your assets in?

If you do, you must understand code, right?"