Aave Hack

TOTAL LOST $56K
Low Access Control Attacks ethereum

What happened

On August 28, 2024, Aave’s periphery contract, specifically the Repay With Collateral Adapter V3, was exploited, resulting in a loss of $56,000 USD across multiple chains.

The vulnerability was rooted in the _buyOnParaSwap function within the Aave Collateral Repay Adapter V3 contract. The function, which interacted with the Paraswap contract, left a high token allowance unadjusted if a swap failed or was only partially executed. This unadjusted allowance allowed the attacker to withdraw unauthorized tokens.

The vulnerability arose because the function did not properly validate or sanitize paraswapData and failed to verify the swap outcome. The attacker crafted malicious paraswapData, manipulating the swap process or avoiding it entirely. By exploiting the unchecked token allowance, the attacker bypassed the intended swap logic, enabling unauthorized fund transfers from the contract.

Exploiter:

https://etherscan.io/address/0x6ea83f23…C296DC

Exploit tx:

https://etherscan.io/tx/0xc27c3ec6…b0e9de

Case & protocol details

Classification Borrowing and Lending / Access Control
Protocol Type Exploit/Other
Smart Contract Language Solidity
Official Website aave.com/
Protocol Twitter/X @aave

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.