Low | Medium | High | Critical | Total | |
---|---|---|---|---|---|
Not fixed | 1 | - | - | - | 1 |
Fixed | 6 | 1 | 2 | - | 9 |
Total | 7 | 1 | 2 | 0 | 10 |
Click to show description
Quick Summary On August 28, 2024, Aave’s periphery contract, specifically the Repay With Collateral Adapter V3, was exploited, resulting in a loss of $56,000 USD across multiple chains. Details of the Exploit The vulnerability was rooted in the _buyOnParaSwap function within the Aave Collateral Repay Adapter V3 contract. The function, which interacted with the Paraswap contract, left a high token allowance unadjusted if a swap failed or was only partially executed. This unadjusted allowance allowed the attacker to withdraw unauthorized tokens. The vulnerability arose because the function did not properly validate or sanitize paraswapData and failed to verify the swap outcome. The attacker crafted malicious paraswapData, manipulating the swap process or avoiding it entirely. By exploiting the unchecked token allowance, the attacker bypassed the intended swap logic, enabling unauthorized fund transfers from the contract. Block Data Reference Exploiter: https://etherscan.io/address/0x6ea83f23795F55434C38bA67FCc428aec0C296DC Exploit tx: https://etherscan.io/tx/0xc27c3ec61c61309c9af35af062a834e0d6914f9352113617400577c0f2b0e9de
# | Name | Auditor | Date | Chains | Issues |
---|---|---|---|---|---|
1 | Aave v3.2 Liquid eModes | OXORIO | 11/09/2024 | Off-Chain (Private) | No active critical issues |
2 | Aave V3 | ChainSecurity | 25/08/2022 | Off-Chain (Private) | No active critical issues |
3 | bridge executors | ChainSecurity | 26/07/2022 | Off-Chain (Private) | No active critical issues |
4 | Aave Protocol V2 | Consensys | 31/08/2020 | Off-Chain (Private) | No active critical issues |
5 | Aave Safety Module | Consensys | 31/08/2020 | Off-Chain (Private) | No active critical issues |
6 | Aave Governance Dao | Consensys | 31/07/2020 | Off-Chain (Private) | No active critical issues |
7 | Aave Token | Consensys | 30/06/2020 | Off-Chain (Private) | No active critical issues |
8 | Aave CPM Price Provider | Consensys | 30/04/2020 | Off-Chain (Private) | No active critical issues |
9 | Aave Protocol Audit | OpenZeppelin | 15/01/2020 | Off-Chain (Private) | No active critical issues |
10 | Aave Protocol Audit | OpenZeppelin | 15/01/2020 | Off-Chain (Private) | No active critical issues |