Aave Hack
What happened
On August 28, 2024, Aave’s periphery contract, specifically the Repay With Collateral Adapter V3, was exploited, resulting in a loss of $56,000 USD across multiple chains.
The vulnerability was rooted in the _buyOnParaSwap function within the Aave Collateral Repay Adapter V3 contract. The function, which interacted with the Paraswap contract, left a high token allowance unadjusted if a swap failed or was only partially executed. This unadjusted allowance allowed the attacker to withdraw unauthorized tokens.
The vulnerability arose because the function did not properly validate or sanitize paraswapData and failed to verify the swap outcome. The attacker crafted malicious paraswapData, manipulating the swap process or avoiding it entirely. By exploiting the unchecked token allowance, the attacker bypassed the intended swap logic, enabling unauthorized fund transfers from the contract.
Exploiter:
https://etherscan.io/address/0x6ea83f23…C296DC
Exploit tx:
https://etherscan.io/tx/0xc27c3ec6…b0e9de
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report blog.solidityscan.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.