Aave founder says V3 unaffected after third-party adapter exploit drains $305K
Source Entity
Cointelegraph by Ezra Reguerra

Two separate cryptocurrency exploits have occurred, involving a major Zano blockchain rollback after unauthorized minting and a $305,000 theft from Aave-linked wallets via a third-party adapter. These incidents highlight critical vulnerabilities in both core protocol security and third-party integrations within the DeFi ecosystem.
Cryptocurrency Security Breaches: An Overview
The decentralized finance (DeFi) landscape has faced significant scrutiny following two distinct security incidents involving the Zano blockchain and an Aave-related third-party adapter. These events underscore the persistent risks associated with smart contract vulnerabilities and the complexities of maintaining network integrity when exploits occur.
The Zano Blockchain Rollback
Zano recently disclosed a severe exploit involving a vulnerability in its Gateway Address, which allowed an attacker to create 36.9 million unauthorized ZANO tokens. The attack occurred in two distinct phases: an initial minting of 18.4 million ZANO on August 29, followed by a second identical minting on September 25. Because these tokens were cryptographically indistinguishable from legitimate ZANO, the development team faced an existential threat to the network's tokenomics, ultimately necessitating a full blockchain rollback of one month to purge the unauthorized supply.
The Anatomy of the Zano Exploit
Beyond the primary ZANO tokens, the attacker also leveraged the vulnerability to mint Freedom Dollar (fUSD) tokens. The fact that these assets successfully entered the Zano ecosystem highlights the difficulty of containment once an exploit is active. The necessity of a blockchain rollback serves as a stark reminder of the 'immutability' paradox in blockchain technology, where radical interventions are sometimes the only mechanism to preserve the value and trust of a project after a systemic breach.
Aave and Third-Party Vulnerabilities
In a separate incident, Aave founder Stani Kulechov confirmed that a $305,000 exploit targeting two Safe multisig wallets did not originate from the Aave v3 protocol itself. Instead, the breach occurred via a third-party adapter designed to facilitate leveraged positions. Security firm SlowMist identified the root cause as an access-control flaw, which allowed a malicious actor to spoof a Safe contract and bypass authorization checks.
Implications for DeFi Security
These incidents highlight a critical trend in blockchain security: while core protocols like Aave v3 are becoming increasingly hardened, the surrounding ecosystem of third-party adapters and peripheral modules remains a significant attack vector. The 'composable' nature of DeFi, which allows developers to build external tools on top of established protocols, introduces complex trust assumptions that attackers are actively exploiting.
Future Trends and Mitigation
Moving forward, the industry is likely to see a heightened focus on rigorous auditing of third-party integrations. For projects like Zano, the incident highlights the need for more robust monitoring of gateway addresses and anomalous minting activity. As the ecosystem matures, the ability to detect such irregularities in real-time will be essential to prevent the need for drastic, network-wide responses like blockchain rollbacks, which disrupt user activity and erode institutional confidence.