Aave founder Stani Kulechov moved quickly to reassure users this week after an attacker exploited a third-party adapter to siphon roughly $305,000 from two Safe multisig wallets, stressing that the core Aave v3 protocol itself remained secure throughout the incident.
What Happened
According to Kulechov, the breach did not stem from any flaw in Aave's own smart contracts. Instead, the attacker targeted a third-party adapter — an external piece of software designed to interact with the protocol — to extract funds from two Safe multisig wallets.
The total loss came to approximately $305,000, a modest figure by the standards of major decentralized finance exploits, but one that once again highlights the risks posed by peripheral integrations rather than base-layer protocols.
The core protocol held firm — the damage came from the edges, not the engine.
Kulechov emphasized that users relying on Aave v3 directly were not exposed to the vulnerability, drawing a clear line between the lending platform's native code and the external tooling built on top of it.
The Broader Risk Picture
The incident underscores a recurring theme in DeFi security: even when a core protocol is battle-tested and audited, the surrounding ecosystem of adapters, bridges, and wallet integrations can introduce fresh attack surfaces. These third-party components often fall outside the direct control of a protocol's development team.
Safe multisig wallets, which require multiple signatures to authorize transactions, are widely used for their added security. However, the exploit shows that even well-regarded custody solutions can be compromised when paired with vulnerable external code.
Key takeaways from the event include:
- Aave v3's native smart contracts were not breached
- The exploit originated from a third-party adapter
- Two Safe multisig wallets were affected, losing about $305,000
For users and developers alike, the episode serves as a reminder to scrutinize not just the protocols they use, but every layer of software that interacts with their funds.
