Aave V3 Cross-Chain Bridge Layer Flagged for High-Severity Security Risks
A DeFi security research team published a risk assessment on September 14, 2026, examining the cross-chain bridge infrastructure of Aave V3, which holds approximately $17.5 billion in total value locked across Ethereum and multiple Layer 2 networks. Auditors identified seven vulnerabilities across the bridge layer, including two high-severity issues: a nonce-handling flaw that could allow replay attacks resulting in duplicate aToken minting, and an unprotected single-owner upgrade path on the Polygon bridge custodying over $5 billion in assets. Three medium-severity findings were also flagged, covering relayer denial-of-service risks, a global supply-cap bypass exploitable across multiple L2s, and missing on-chain proof-of-liquidity verification. Researchers warned that while no single flaw is trivially exploitable alone, a coordinated multi-vector attack could potentially result in losses exceeding $1 billion. The assessment noted that these bridge-layer risks fall outside the scope of Aave V3's existing core contract audits.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in