A third-party lending adapter built on top of Aave was exploited on October 2, resulting in the theft of approximately 114 ETH, valued at over $300,000. The attack targeted the FlashLoopAdapter, a tool used in conjunction with the Aave protocol, rather than Aave's core smart contracts.

Blockchain security firm SlowMist first identified the incident, reporting that the attacker compromised two Safe multisig wallets through a vulnerability in the FlashLoopAdapter CryptoSlate. The exploit specifically involved the adapter's handling of flash loans, a common DeFi mechanism that allows users to borrow without collateral as long as the loan is repaid within a single transaction block.

Aave founder Stani Kulechov confirmed that Aave v3 remained completely unaffected by the incident Cointelegraph. The distinction between the third-party adapter and Aave's native protocol has become a critical point in understanding the scope of the damage, as initial reports sometimes conflate external integrations with core protocol failures.

The FlashLoopAdapter serves as an intermediary layer that enables more complex lending strategies on Aave, including automated looping of collateral to amplify positions. These adapters, while extending functionality, introduce additional attack surfaces that exist outside of Aave's formal security guarantees. The exploited wallets were reportedly managed through Safe, formerly Gnosis Safe, a popular multi-signature wallet infrastructure widely used by DeFi protocols and treasury management.

The $305,000 loss represents a relatively modest sum by DeFi exploit standards, though it underscores persistent risks in the composable finance ecosystem where protocols frequently interact with external contracts. Flash loan attacks have become a recurring vector in DeFi security incidents, exploiting price oracle manipulation, reentrancy vulnerabilities, or logic errors in contract interactions.

Security researchers emphasize that users interacting with third-party adapters bear distinct risks compared to direct protocol usage, as these tools may not undergo the same auditing and governance processes as established lending platforms. The incident adds to a growing catalog of adapter and wrapper contract exploits that have affected major DeFi protocols while leaving underlying markets intact. No user funds on Aave v3 were reported at risk during the event.