Aave v3 Exploit Drains Two Safe Wallets for $305K
The $305K is small for an Aave v3 incident; the concern is the access-control bug in FlashLoopAdapter sitting inside a module Safe multisigs opt into by default.
Every Zipp story tagged #Exploit, newest first.
The $305K is small for an Aave v3 incident; the concern is the access-control bug in FlashLoopAdapter sitting inside a module Safe multisigs opt into by default.
The 114 ETH drain is small in size. The bigger read is the access-control failure in FlashLoopAdapter that bypassed Safe authorization, because a Safe is only as secure as the modules it ships.
Public identification plus a hard 48-hour clock is the template more protocols are copying. The next move is law enforcement referrals and on-chain pursuit, not further negotiation.
A patch and full reimbursement pledge limit the immediate fallout, but deposits and withdrawals across supported chains face a roughly 12-hour suspension.
The April 22 attack drained 116,500 rsETH and helped trigger a $20B DeFi deposit exodus, putting bridge security and accountability under scrutiny.
296.4 ETH has been returned to the DAO multisig, but the plan still lacks a Snapshot vote, per-pool allocation tables and a claim window, leaving LP payouts undefined.
The loss exposed a protocol-level authorization flaw, while a 10-day halt and missed 2024 audit raise questions about maintenance code and emergency controls.
Six double-paid withdrawals drained 736,442.17 USDT from Chainflip's TRON vault via a malformed memo. Patch is live; affected LPs sit at zero balance with no funding source or repayment timeline.
Even after team cuts and a v3 rebuild, revenue never recovered from the Nov. 2025 $128M hack. A Sept.
Trading is back, but the federation's authorized route back to BTC is still closed. The ~627 BTC gap and absence of redemption arbitrage turn L-BTC's price into a confidence signal rather than proof…
Self-custody holders are the ones with no recovery path, and the venue-by-venue patchwork is the new playbook for token migrations after exploits.
Blockstream is calling the 10% demand 'theft, not white-hat disclosure.' The refusal draws a hard line on whether open-source Bitcoin infrastructure pays bug-bounty blackmail at all.
Two attacks in three years were too many. The rollback now reads less like recovery and more like a brief delay before Harmony gives up its chain entirely.
Liquid issues L-BTC against bitcoin locked in reserve to speed up exchange settlements, so a near-total drain of that reserve forces every federation member to answer whether the model itself is…
The foundation called it 'upgraded, not halted,' but the emergency patch touched core protocol modules, jailed validators, and forced Coinbase and Coins.ph to pause transfers.
The Mango Markets playbook strikes twice in four days, draining two lending markets through the same illiquid-token loophole that cost Avraham Eisenberg's victims $116M in 2022.
The breach wasn't in user-controlled wallets. It hit the third-party contract holding card-loaded funds, the exact handoff crypto-card spending depends on as volumes triple.
The pause breaks a project that, as recently as March, advertised 100% mainnet uptime on its own website, and the Foundation has yet to name the attack vector, the targeted addresses, or a restart…
Four-month triage miss is the bigger story. Cosmos Labs assumed 18-decimal chains were safe, six networks got drained, and disclosure norms for the $7B Cosmos stack just got rewritten.
The team says user funds were insulated from the pause, but the asset impact of the attacker's activity remains unconfirmed.