Aave V3 security incidents
-
Fractal Protocol hacked
Fractal Protocol's USDF vault on Arbitrum was exploited due to a smart contract logic flaw, resulting in the loss of approximately 13,700 USDC.e. The exploit involved a flash loan and re-entrant calls that manipulated accounting issues.
-
Custom sAVAX Aave Rebalancer contract hacked
A custom sAVAX Aave Rebalancer contract on Avalanche was exploited via a smart contract vulnerability, allowing an attacker to drain user funds. A whitehat bot frontran the exploit and recovered all funds, resulting in zero net loss to the user.
-
Aave V3 — Oracle Misconfiguration
Aave V3 experienced an oracle misconfiguration by Chaos Labs, which undervalued wstETH by approximately 2.85%. This led to wrongful liquidations on 34 positions, resulting in losses of about $862,000. Aave DAO compensated affected users.