|

Crypto hackers exploit third-party Aave tool to steal 114 ETH

A third-party lending adapter constructed on Aave was exploited to steal about 114 ETH, price over $300,000, whereas the protocol itself remained unaffected.

On Oct. 2, blockchain safety agency SlowMist said the attacker compromised two Safe multisig wallets by a flaw within the FlashLoopAdapter used with Aave v3 positions. The exploit allowed the attacker to bypass the adapter’s authentication checks, execute arbitrary calls, and drain collateral from the affected wallets.

SlowMist estimated the direct loss at about 114.09 ETH. It stated roughly 1,300 WETH of debt was additionally repaid throughout the assault to unlock collateral tied to the positions.

Aave founder Stani Kulechov stated the incident didn’t contain Aave v3’s core good contracts. He said:

“This just isn’t Aave v3 contract, it’s third social gathering exterior adapter constructed on prime of Aave, zero impact on Aave v3.”

The distinction is critical for Aave, the largest decentralized lending protocol, with greater than $33 billion in whole worth locked. The exploit affected infrastructure layered on prime of Aave.

Fake Safe bypass opened entry to collateral

SlowMist traced the vulnerability to the FlashLoopAdapter’s open() and shut() features, which checked whether or not the calling Safe had enabled the adapter as a module.

That verification could possibly be spoofed.

Related Reading

Why DeFi giant Aave is pulling the plug on six hyped blockchains making less than $5,000 a quarter


According to SlowMist, the attacker created a pretend Safe contract that all the time returned a constructive response when requested whether or not the module was enabled. The adapter then accepted the solid authentication and proceeded to its inner swap perform.

The extra severe weak point got here subsequent. The adapter allowed the caller to specify each the router and calldata utilized in an exterior contract name.

The attacker pointed the router again on the sufferer Safe and provided directions invoking Safe’s execTransactionFromModule perform. Because the FlashLoopAdapter was already enabled as a module on the affected wallets, that decision gave the attacker a path to execute transactions by the victims’ Safes.

SlowMist stated the method was used to withdraw weETH and collateral related to Aave positions from two multisig wallets.

The incident highlights a recurring danger in decentralized finance: protocol safety can stay intact whereas integrations constructed round it create separate assault surfaces.

For Aave, the quick publicity seems contained to customers of the weak adapter. The subsequent query is whether or not different wallets enabled the identical module and whether or not the adapter’s builders determine extra affected positions earlier than attackers can reuse the identical authentication flaw.

The submit Crypto hackers exploit third-party Aave tool to steal 114 ETH appeared first on CryptoSlate.

Similar Posts