Aave’s V2 protocol on Ethereum suffered a targeted exploit against two deprecated lending markets, resulting in the theft of roughly $229,000 from the aUSDT and aSTETH pools. The incident was disclosed by security researcher Exvuln on X, who described it as a security breach affecting legacy Aave V2 markets rather than the actively maintained V3 deployment. On‑chain data linked in the disclosure shows a series of transactions draining funds from the affected aToken contracts into an attacker-controlled address, with the loss size estimated in the low six figures. The exploit appears to have been localized to these specific V2 pools, with no evidence (as of reporting) of contagion to other Aave markets. The event comes against the backdrop of prior Aave security actions, including a critical‑severity V2/V3 vulnerability reported via the Immunefi bug bounty in November 2023 that led the Aave Guardian to pause V2 Ethereum and freeze or pause selected assets on V3 chains as a precaution. In that earlier case, the issue was mitigated before it could be exploited and subsequently addressed through governance measures such as disabling stable‑rate borrowing on affected markets. The new V2 exploit underscores that even heavily audited and battle‑tested DeFi protocols like Aave, which maintain ongoing bug bounty programs and third‑party audits, still carry residual smart‑contract and market‑design risks—particularly in older or partially deprecated deployments that may not receive the same level of active risk management. For users, the incident highlights the importance of understanding which protocol versions and markets remain fully supported, how emergency controls (pauses, freezes) work, and the continuing need for security monitoring around legacy DeFi infrastructure.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on $aUSDT

Comments