Aave founder Stani Kulechov confirmed that the core protocol remained completely unaffected following a security breach targeting a third-party module. The incident took place on October 2, 2026, when an attacker targeted an external adapter connected to the platform.
🚨SlowMist TI Alert🚨
💸 @aave v3 Loop Safe Module Loss: ~114.09 ETH
🔍 Root Cause: FlashLoopAdapter's open()/close() access control only checks ISafe(msg.sender).isModuleEnabled(address(this)), which is spoofable via a fake Safe that always returns true. Its _swap() then…
— SlowMist (@SlowMist_Team) October 2, 2026
The exploit targeted two Safe multisig wallets, resulting in losses totaling 305,000 dollars in digital assets, according to data shared by blockchain security firm SlowMist via an official statement.
Hackers exploited an access-control vulnerability within the FlashLoopAdapter smart contract. This flaw allowed a fraudulent Safe contract to bypass the system authorization checks successfully.
Preliminary investigations indicate the manipulated code granted the attacker control over the router and transaction execution data. This capability enabled the malicious execution of swaps within the compromised accounts.
During the digital intrusion, the attackers repaid 1,300 WETH tokens in debt to unlock trapped collateral. Afterward, they stole 114,09 ETH from the exposed multisig wallets.
The security event unfolds while the ecosystem discusses architectural changes, similar to the topics explored in this overview of DeFi governance evolution.
This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.
— Stani (@StaniKulechov) October 2, 2026
Kulechov distanced the core platform from the event through a verified message, emphasizing that the underlying infrastructure operates securely without disruption.
Security operations remain focused on addressing vulnerabilities in peripheral tools. These measures align with broader ecosystem maintenance efforts, such as previous initiatives involving low-use reserve cleanups across various networks.
Audits of the affected wallets remain ongoing as developers update security logs for the compromised adapter.
This article is for informational purposes only and does not constitute financial advice.

