News linked to both this project and an event.
A crypto asset vault on Base had approximately 1,783 wstETH transferred out on October 4, resulting in losses exceeding $6 million. On-chain records show that the vault is controlled by a 3-of-7 Safe, and the identities of the seven signers have not yet been made public.Security firms stated that the attacker borrowed aBaswstETH from the vault and swapped it for wstETH through Aave. Neither the Base chain itself nor Aave's core contracts have been identified as being exploited, and the specific authorization vulnerability remains unconfirmed. (Bitcoin.com News)
according to monitoring by Stani Kulechov, Aave founder Stani Kulechov stated that what was exploited was a third-party external adapter built on top of Aave v3, and the Aave v3 contracts themselves were not affected. The FlashLoopAdapter in the Aave v3 Loop Safe module involved had access control vulnerabilities in its open() and close() functions. The attacker forged Safe authentication and arbitrary module execution to steal approximately 114.09 ETH from two Safe multisig addresses, and repaid approximately 1,300 WETH in debt to unlock collateral.
SlowMist has issued a security alert stating that a vulnerability has been discovered in the Aave V3 Loop Safe Module. Attackers exploited forged Safe authentication and arbitrary Module execution to steal approximately 114.09 ETH from two Safe multisig wallets.The attackers bypassed authentication by forging a Safe that always returns true, and leveraged an arbitrarily controllable router and calldata to execute module transactions, transferring weETH and Aave collateral. The attackers repaid approximately 1,300 WETH in debt to unlock the collateral.
Aave founder Stani stated on X that the team is tracking the developments of the MetaMask staking infrastructure security incident in collaboration with Lido. Stani noted that so far, the Aave market has not been affected by the incident, and all operations remain fully operational.
Odaily News, SlowMist Security Team disclosed that the cross-chain bridge project Allbridge suffered an attack on August 19, 2026, with losses of approximately $190,000. Notably, this attack was not executed instantaneously—the attacker began laying the groundwork nearly a month in advance, bypassing the verification mechanism through forged cross-chain messages.According to SlowMist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as CCTP-style, claiming a transfer of 1 million USDC, despite no actual USDC burn operation occurring. Subsequently, Circle generated a valid attestation for this complete message following standard procedures.Approximately 24 days later, on August 19, the attacker waited for the Base Router to receive a genuine CCTP deposit, bringing its balance to approximately 191,000 USDC, then launched the attack just 6 seconds later. Using the previously forged message and attestation, the attacker called Allbridge's receiveCctpMessage function. Due to the project's lack of critical validation, the system mistook the fraudulent cross-chain message for a genuine deposit and recorded a 1 million USDC credit.Subsequently, the attacker borrowed approximately 809,000 USDC temporarily via an Aave flash loan to match the Router's balance with the forged amount, then utilized the internal credit record to call the transfer function, ultimately moving out approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800 in profit. The root cause of this vulnerability lies in Allbridge's failure to verify the identity of the cross-chain message sender and receiver, as well as its failure to confirm whether USDC was genuinely minted or whether the balance actually increased—instead directly trusting the amount and message hash data constructed by the attacker.SlowMist emphasized that on-chain message verification does not equate to actual asset arrival. Cross-chain protocols must not only verify message authenticity but also ensure the message source is trustworthy, confirm the receiver is Circle's official TokenMessengerV2, and only record assets after confirming actual minting and balance changes. This incident once again highlights the security risks in cross-chain bridges' message verification and asset settlement processes.
Odaily News: Standard Chartered initiated coverage on Monday of blockchain oracle project Chainlink, projecting LINK to reach $200 by the end of 2030 — roughly 25 times its current price of around $8. The bank's phased targets are $13 by the end of this year, followed by $41, $82, and $133. Standard Chartered estimates that the on-chain tokenized asset market will reach $4 trillion by the end of 2028, with DeFi-deployed assets hitting $2.7 trillion by 2030 — a 37-fold increase from current levels. The bank expects Chainlink fees to grow approximately 25-fold over the same period, assuming token prices track fee growth. Chainlink secures over $110 billion in total value, covering approximately 70% of the value that global DeFi relies on from oracles, with a share exceeding 80% on Ethereum; Aave V3 accounts for 44% of that. Swift, DTCC, Euroclear, JPMorgan, Mastercard, UBS, Fidelity, and S&P Global are all listed as institutions using its services. Chainlink still lags behind LayerZero in cross-chain interoperability. Following the $292 million attack in April, over $7 billion in token value has migrated to Chainlink CCIP, with second-quarter transaction volume reaching $4.9 billion — up 353% year-over-year. Risks include slowing institutional tokenization, pilots not converting to production processes, and technical failures impacting confidence. (Decrypt)
Aave founder Stani Kulechov has responded to reports suggesting Kraken's parent company Payward is interested in acquiring a 15% stake in the Aave protocol, stating that AAVE is "not going to be sold at a 70% discount."Prior reports from CoinDesk indicated that Payward was in talks to acquire a 15% stake in Aave at a valuation of $385 million. If calculated at this valuation, it would represent only approximately 30% of AAVE's fully diluted valuation, significantly below the market valuation.In a post on X, Kulechov stated that the relevant reports were not entirely accurate. He did not completely deny the possibility of Aave Labs selling a portion of its held AAVE tokens, but noted that Aave Labs does have a certain allocation of AAVE, and that multiple market participants have discussed purchasing either directly or indirectly, or engaging in deeper collaboration centered around long-term partnerships.Aave is the largest decentralized lending protocol on the Ethereum ecosystem. Kulechov stated that Aave currently generates an annualized revenue of approximately $134 million, with the relevant revenue flowing to the Aave DAO. He has also previously proposed a governance plan to redirect revenue from Aave Labs, the protocol, and its products to the Aave DAO and token holders.These rumors emerge at a time when Aave is experiencing certain pressures. Following the Kelp DAO incident in April, Aave's TVL saw a significant decline. Although Aave itself was not directly attacked, the KelpDAO cross-chain bridge attacker utilized Aave to convert the stolen rsETH into other assets.
According to CoinDesk, Geoff Kendrick, Head of Digital Asset Research at Standard Chartered Bank, released a report initiating coverage of the decentralized lending protocol Aave, with a target price of $3,500 by end-2030—approximately 50 times its current price of around $70—and expects Aave to outperform both Bitcoin and Ethereum. Kendrick stated that Aave has recovered from the April 2026 KelpDAO rsETH bridge vulnerability incident, during which attackers used approximately $290 million worth of stolen tokens as collateral to borrow real assets on Aave, exposing the protocol to up to $230 million in potential losses. Assets have now begun flowing back onto the platform, and Aave’s dominant position in on-chain lending remains solid. Looking ahead, Standard Chartered forecasts that the value of tokenized assets actively used in DeFi applications will grow 37-fold by 2030. Aave—whose revenue model is directly tied to lending activity—is poised to benefit directly. Additionally, Aave’s Horizon initiative (enabling tokenized real-world asset lending in permissioned environments) and the potential relaunch of its token buyback program are viewed as key catalysts.
Odaily Aave, a DeFi lending protocol, successfully maintained operations after experiencing capital outflows totaling approximately $8.45 billion. However, the incident has simultaneously triggered renewed market discussion regarding its risk structure and the fragility of the DeFi system.This stress event originated from a vulnerability exploit on the KelpDAO rsETH cross-chain bridge in April 2026, resulting in the theft of approximately $292 million in assets. This triggered market concerns over the safety of rsETH collateral. As this asset was widely used as collateral on Aave, panic spread rapidly, leading to concentrated withdrawals by users.During the capital outflow process, liquidity in certain lending markets was quickly depleted, with utilization rates briefly approaching 100%. Aave managed the situation by adjusting risk parameters and activating emergency mechanisms, although localized withdrawal restrictions did occur.Nevertheless, Aave's core smart contracts were not compromised. Protocol founder Stani Kulechov stated that the event validated the system's stability and resilience under extreme stress conditions.However, analysts pointed out that this incident exposed structural risks within DeFi: high coupling of assets across protocols, reliance on external bridged assets for collateral, and the potential for liquidity to rapidly evaporate in extreme scenarios.Industry observers believe that while DeFi's "composability" enhances efficiency, it also accelerates risk transmission, potentially causing a single asset event to trigger systemic cascading effects. Although Aave successfully navigated this stress test, the outcome does not equate to the elimination of risk.Overall, this event is viewed as a genuine extreme stress test for the DeFi lending system: the system can function, but its stability remains highly dependent on the quality of external assets and the market liquidity environment. (Cointelegraph)
According to on-chain analyst Yu Jin (@EmberCN), the attacker responsible for the March THE liquidation event on the Venus platform sold 1,912 ETH for $3.26 million one hour ago to repay part of their loan on Aave. That loan was originally taken out by collateralizing ETH and was used to manipulate the Venus liquidations. The attacker’s address still has $6.78 million in USDT outstanding on Aave.
in April this year, KelpDAO's LayerZero bridge was exploited in a $292 million vulnerability attack, triggering an $8.45 billion deposit run on Aave within 48 hours, marking the largest capital outflow event in decentralized finance (DeFi) history. Aave founder Stani Kulechov stated that the design of Aave V3 withstood the market test, demonstrating the network's "resilience." However, independent data indicates that Aave's survival primarily relied on $300 million in emergency rescue, including a 25,000 ETH guarantee from the Aave DAO and a personal injection of 5,000 ETH (approximately $8.4 million) by Kulechov.Kulechov attributed the vulnerability to third-party infrastructure rather than core smart contracts. However, analysts pointed out that this incident exposed deficiencies in Aave's risk architecture and insurance mechanisms, leading the platform to incur significant bad debt (approximately $123.7 million in wETH). To prevent future bridge failures from triggering systemic bank runs, Aave V4 will adopt a modular "hub-and-spoke" architecture, enabling local risk auto-adjustment and collateral freezing. (CoinDesk)
Aave has published a post-mortem of the April 18 rsETH incident, stating that the rsETH LayerZero V2 cross-chain bridge of liquid staking protocol Kelp accepted a forged message during a cross-chain transfer from Unichain to Ethereum. This caused the adapter on the Ethereum side to release 116,500 rsETH without a corresponding burn on the Unichain side. Aave stated that the attack occurred on a third-party cross-chain bridge infrastructure. However, the attacker deposited the stolen rsETH into 8 Aave V3 positions, borrowing 82,650 WETH and 821 wstETH, which impacted the Aave market.Aave stated that the attacker's rsETH on Arbitrum has now been burned. The LayerZero OFT adapter has replenished 116,131.72 rsETH in 5 batches, and the asset backing for rsETH has been fully restored. The affected WETH and rsETH markets have returned to normal.
Odaily Kelp announced on X platform that it has coordinated with multiple DeFi protocols to complete the liquidation of the attacker's positions, achieving key progress in the rsETH recovery process. Among them: Compound participated in coordination multiple times over the past four weeks, providing approximately 3,000 ETH in support, and jointly completed the liquidation with Aave, recovering a total of approximately 17,426.20 rsETH; Euler Finance liquidated the attacker's positions within its protocol and plans to return the excess ETH to the DeFi ecosystem fund.
in April 2026, two major DeFi attacks on Drift Protocol and Kelp DAO resulted in losses of nearly $600 million, triggering approximately $9 billion in capital outflows from protocols like Aave. TRM Labs investigator Nick Carlsen stated that a hacker group suspected to be linked to North Korea has allegedly used AI to assist in target selection and attack path design. Failsafe CEO Aneirin Flynn said that AI has compressed the time for discovering blockchain vulnerabilities from months to days or even hours. The report noted that Anthropic has not fully opened its AI model Mythos due to cybersecurity risks, claiming the model has the capability to discover large-scale zero-day vulnerabilities. Its research indicates that over half of blockchain attacks in 2025 could theoretically be completed autonomously by AI. (Bloomberg)
that, according to official sources, AaveLabs has proposed restructuring the Aave DAO bug bounty framework into multiple specific subsystem programs, operating on the Immunefi, Sherlock, and Cantina platforms respectively. Core Aave V3, Core Aave V2, GHO, and non-liquidity protocol infrastructure will be covered by Immunefi; Aave V4 and the Aave App Stack will be covered by Sherlock; and Aave V3 on Aptos will be covered by Cantina.The proposal suggests adjusting the bounty scale for each system. The maximum reward for critical vulnerabilities in Core Aave V3 is $5 million, while the maximum reward for critical vulnerabilities in Aave V4 is $2.5 million. Additionally, the funding source for the Aave V3 bug bounty on Aptos will be transferred from Aave Labs to the Aave DAO. This ARFC proposal has currently been passed.
Aave announced that its bug bounty program has been updated to better align rewards with the risk profile of each component within the ecosystem and to streamline the review process. The reward cap for critical vulnerability fixes in Aave V4 and Core Aave V3 has now been increased fivefold.
Odaily Odaily News Gate Research recently released its "April 2026 Cryptocurrency Market Review" report, indicating that the overall cryptocurrency market saw a volatile upward trend in April, with total market capitalization significantly higher than in March. BTC and ETH ETF trading volumes maintained high volatility overall. The report shows continued divergence in activity across major public chain ecosystems. Solana's daily transaction volume remained in the range of approximately 90 million to 110 million transactions, maintaining its leading position.Regarding trending sectors, the report notes that Pokemon TCG RWA has become one of the fastest-growing on-chain RWA sub-sectors, entering a second explosive growth phase in April. Major trading platforms saw monthly trading volumes exceed $220 million, with weekly revenue briefly approaching $6 million, setting new historical records. Meanwhile, Aave experienced its most severe liquidity crisis ever in April, with TVL outflows reaching tens of billions of dollars within a few days and net outflows exceeding $9 billion for the entire month.In terms of fundraising and security incidents, the Web3 industry completed 51 financing rounds in April, totaling approximately $834 million, with capital further concentrating on leading financial and infrastructure tracks. Among these, Payward ranked first for the month with a $200 million financing round. On the security front, Web3 security incidents in April resulted in losses of approximately $306 million, a month-over-month increase of about 858%, primarily driven by a single cross-chain infrastructure attack on Kelp DAO worth approximately $293 million. The report suggests that against the backdrop of a recovering market, on-chain activity and capital liquidity are both increasing simultaneously. However, the security risks associated with cross-chain infrastructure and high-leverage protocols remain worthy of continued attention.
According to Cointelegraph, a New York judge has postponed the hearing on Aave’s emergency motion to unfreeze approximately $71 million worth of ETH and ordered Aave and Gerstein Harrow LLP to submit additional case briefs. A new hearing is scheduled for June 5. The court noted that Aave previously failed to adequately explain why users’ funds would suffer “derivative losses” if the restraining order remained in effect. The assets in question are linked to the Kelp DAO hack, which involved approximately $293 million and was previously frozen by Arbitrum. The judge also directed both parties to further clarify several legal issues, including the applicable law governing the hacker’s transactions, the legal distinction between fraud and theft, the priority ranking of creditors’ claims, the applicability of constructive trust, and whether assets can be proportionally returned to victims.
Aave posted on X, stating that the first phase of the rsETH technical recovery plan has been completed, including the burning of the attacker's rsETH on Arbitrum.In the coming days, funds will be gradually replenished for the LayerZero OFT adapter, and rsETH-related operations will be restored.
Odaily News: Margaret Garnett, a U.S. District Judge in Manhattan, has approved Aave's asset recovery proposal, allowing the transfer of approximately $71 million in ETH previously frozen on Arbitrum and linked to North Korean-linked attacks, to a wallet controlled by Aave LLC, while preserving the legal claims of terrorism victim plaintiffs over the funds. The ruling also amended the earlier freeze notice against the Arbitrum DAO, permitting the transfer to be executed through an on-chain governance vote and exempting those who propose, vote on, or participate in the transfer from liability under the freeze order. The transfer is still subject to an official vote by Arbitrum's on-chain governance. (CoinDesk)