Aave reports v2 vulnerability, pauses v2 contracts, and funds are safe - but v2 forks may still be at risk


1 recorded changes
Want your article here?
Promote with Leviathan News

1 recorded changes
Want your article here?
Promote with Leviathan NewsIn early November 2023, Aave disclosed that a critical vulnerability had been reported through its bug bounty program affecting the Aave v2 protocol on Ethereum and some Aave v3 deployments on Optimism, Arbitrum, Avalanche, and Polygon. In coordination with the Aave Guardian, the team immediately applied emergency protections: Aave v2 Ethereum was paused and several assets on v3 markets were frozen or paused, while stable-rate borrowing was disabled to neutralize the attack vector. Aave emphasized that the issue was reported responsibly, that it had not been exploited, and that user funds on official Aave deployments remained safe and withdrawable throughout the event. Because Aave v2 and v3 have been widely forked by third-party projects, the team initially withheld full technical details of the bug to avoid giving attackers a blueprint against unaudited forks that might not adopt the same protections. The long‑term mitigation plan included governance proposals to permanently disable new stable debt minting across instances where stable rate borrowing was active and to introduce a “Liquidations Grace Sentinel” to manage liquidation risk when assets are paused and later unpaused. After governance execution and phased unpausing, Aave reported that all v2 and v3 pools had returned to normal operations with no user losses, effectively closing the disclosure event on the core Aave markets, even as forked deployments were advised to review and harden their own implementations.
AI-generated background, compiled from web sources — not editorial content.

𝕏/@aave ·

𝕏/@aave ·

𝕏/@pendle_fi ·

𝕏/@aave ·

Aave ·

Galaxy ·

𝕏/@aave ·

𝕏/@aave ·

𝕏/@pendle_fi ·

𝕏/@aave ·

Aave ·

Galaxy ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?