Cryptocurrency

"Aave Users Unable to Access Over $100M in Assets Due to Bug"

2023-05-19 [vendor] Polygon Aave bug [chain] polygon
Primary Source ↗
Blockchain(s) Polygon

Incident Details

Recently, the Aave protocol deployed a contract upgrade on the Polygon version of their v2 project that was not compatible with Polygon. The bug has resulted in around $110 million of funds in wETH, wBTC, USDT, and wMATIC being “stuck”, meaning users can’t perform any actions involving those funds.The funds are not at risk, but it will take at least a week before the funds are unstuck because any code change requires a DAO vote. “Considering governance times, if approved, the fix will be applied in approximately 7 days from now: 1 day of delay to start voting, 3 days of voting, 1 day of timelock on Ethereum, and 2 extra days of timelock on Polygon,” explained a post by Bored Ghost Developing, a contributor to Aave.

Technical Details

Initial Attack Vector
Software bug / unintentional loss
Vendor / Product
Polygon Aave bug

Timeline

  1. 2023-05-19 Breach occurred
  2. 2023-05-19 Publicly disclosed