Aave Adapter Exploit and DeFi Peripheral Contract Security
Summary
The document reviews the exploit of Aave’s ParaSwapRepayAdapter, a peripheral contract intended to repay borrowing by swapping collateral through decentralized exchanges. It attributes the attack to positive slippage that left tokens available to the attacker. QuillAudits estimated losses at about $51,000 across Ethereum, Arbitrum, Polygon, and Optimism, with another $5,000 on Avalanche. Aave stated that the incident did not affect its core protocol or user funds.
The article uses the incident to highlight security risks in auxiliary contracts, especially where swap logic and arbitrary calls are involved. It also describes criticism of Aave’s transparency and a public dispute with Euler Finance, including reference to Euler’s earlier hack. Its broader recommendations are to audit peripheral contracts, communicate clearly about incidents, and coordinate on security practices. The technical account is thin: it provides little detail about the exploit path, contract behavior, or verification of the stated losses, so it is an incident overview rather than a reproducible security analysis.
Key ideas
- Peripheral DeFi adapters can create risks even when a protocol’s core contracts remain unaffected.
- The reported ParaSwapRepayAdapter exploit involved leftover tokens associated with positive swap slippage.
- The document reports estimated losses across several networks but gives limited technical evidence about the attack.
- Auditing auxiliary contracts and communicating clearly about incidents are presented as security priorities.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.