Aave Adapter Flaw Lets Attacker Drain 114 ETH From Safe Wallets
Aave v3’s core contracts were unaffected, but the attack exposed how a third-party integration can put collateral in users’ wallets at risk.
Every Zipp story tagged #Multisig, newest first.
Aave v3’s core contracts were unaffected, but the attack exposed how a third-party integration can put collateral in users’ wallets at risk.
The 114 ETH drain is small in size. The bigger read is the access-control failure in FlashLoopAdapter that bypassed Safe authorization, because a Safe is only as secure as the modules it ships.
The draft targets wallet metadata that seed phrases cannot recover, but an exposed eligible xpub could also unlock the encrypted backup and reveal its script structure.
The 5-of-8 multisig can only cancel malicious transactions during the two-day timelock; treasury control stays with token holders, and the authority sunsets automatically unless DAO votes to extend.
The launch lands ahead of any concrete quantum threat to Bitcoin's secp256k1 curve, but it gives institutions a framework to triage UTXO exposure now, before the timeline forces a decision.
The breach wasn't a novel attack — it was a textbook custody failure on a project backed by Pantera and Jump Crypto, and the recovered token price is still a third of pre-breach levels.
He points to gaps in understanding both the math and the practical deployment of PQC signature schemes, and outlines wallet-level mitigations Solana could ship.
The first-ever 9-of-12 emergency multi-sig execution on a major L2 sets a precedent the rest of DeFi will now have to argue about.