$305K Gone in Minutes, and the Exploit Wasn't Even Aave's Fault
A third-party adapter connected to Aave just handed an attacker $305,000 stripped from two Safe multisig wallets, and most of crypto Twitter barely flinched.
Aave founder Stani Kulechov moved quickly to clarify that Aave V3 itself was never touched. The protocol held. The money that vanished sat inside Safe multisig wallets, routed through an external adapter that nobody was watching closely enough.
That distinction matters, but it does not make the story less alarming.
The Real Problem Nobody Is Naming
DeFi's composability is its superpower. It is also its most dangerous vulnerability. Every time a protocol plugs into a third-party adapter, bridge, or wrapper, it inherits that component's risk surface whether it wants to or not.
Aave V3 surviving this exploit is good news. But users who had funds sitting in those Safe wallets interacting with that specific adapter did not survive it. $305,000 is gone.
The attacker did not need to break Aave. They just needed to find the weakest link in the chain, and third-party adapters are almost always that link.
Why This Pattern Keeps Repeating
This is not a one-off. The DeFi graveyard is full of protocols that survived their own audits but collapsed because something adjacent to them failed. Curve, Euler, Radiant, and now this. The core protocol holds up while the edges bleed out.
What makes this case particularly sharp is the target: Safe multisig wallets. These are supposed to be the secure option, the setup that serious funds and DAOs use specifically because they want multiple layers of protection. If attackers are now successfully routing exploits through adapters connected to Safe wallets, that is a meaningful escalation in targeting.
What Kulechov's Reassurance Actually Tells You
When a founder immediately goes public to confirm a protocol is unaffected, it usually means two things. First, the team is competent and monitoring. Second, the optics risk was real enough to require a fast response.
Kulechov did the right thing. But the speed of that clarification also signals how close to the core this felt.
What to Watch Right Now
If you are using any DeFi protocol through a third-party adapter, wrapper, or integration layer, now is the time to audit exactly what that connection looks like and who maintains it.
Aave V3 is fine. Check everything around it.
Monitor whether on-chain forensics identify the attacker's wallet and whether funds move to a mixer in the next 24 to 48 hours. That will tell you if this was opportunistic or coordinated.
The protocol survived. The question is whether the ecosystem learned anything.