Aave contributors disclosed on November 4, 2023 that the protocol had received a bug-bounty report describing a vulnerability initially classified as high severity and subsequently raised to critical. The Aave Guardian responded by pausing the Aave V2 Ethereum market and freezing selected assets on V3 deployments while contributors prepared a governance-led remediation.

BGD Labs, an Aave DAO service provider coordinating the response, said the reported attack vector could affect some assets in Aave V2 on Ethereum and Aave V3 on Optimism, Arbitrum, Avalanche and Polygon. It also said disabling stable-rate borrowing prevented exploitation of the issue.

No exploit or loss had been identified when the incident was disclosed. That was a contemporaneous assertion from protocol contributors, not an independently completed forensic finding.

What users encountered

The emergency response did not shut down every Aave deployment. Contemporaneous reporting described Aave V2 on Ethereum as paused, with selected V3 assets frozen on Polygon, Arbitrum and Optimism. Aave V3 remained operational on Ethereum, Base and Metis, while V2 markets on Polygon and Avalanche were not included in that reported pause.

A pause is operationally significant even when it prevents theft. Depending on the affected market and configuration, users can lose the ability to supply, withdraw, borrow, repay or liquidate positions until restrictions are removed. Freezing an asset is narrower: existing positions remain, but specified new activity is restricted.

Those controls therefore exchanged immediate market availability for protection against an undisclosed attack path. The distinction mattered because Aave was not reporting missing funds; it was reporting a credible vulnerability and a defensive interruption designed to stop potential exploitation.

Why the response mattered

Aave’s response illustrated the institutional structure behind a nominally decentralized lending protocol. Token governance controlled permanent configuration changes, but emergency authority delegated to the Guardian allowed protective action before a full proposal could complete voting and execution delays.

That arrangement can reduce response time when public disclosure would expose users and protocol forks to an attack. It also creates governance questions: who can interrupt markets, which operations become unavailable, how quickly normal service can return, and what protections borrowers receive if prices move while repayment or collateral management is blocked.

The vulnerability’s connection to stable-rate borrowing was particularly consequential. Stable-rate mode was a protocol-defined borrowing option, not a promise that a borrower’s rate could never change. On November 4, BGD Labs proposed disabling the mode for assets and deployments where it remained active. Aave governance proposal 358 was created at 22:34 UTC with instructions covering Aave V2 Ethereum and V3 deployments on Polygon, Avalanche, Optimism and Arbitrum.

What remained uncertain on November 4

Contributors withheld the vulnerable code path because Aave V2 and V3 had been copied by third-party protocols. That limited outside verification but reduced the risk that disclosure would become an attack guide before forks could respond.

The November 4 record therefore established the report, severity assessment, affected protocol feature and emergency measures. It did not independently prove that every exposed fork had been protected, that no attempted exploitation had occurred anywhere, or how long all restrictions would remain in force.

Later context

Aave governance records show proposal 358 was executed on November 9, 2023. Subsequent remediation upgraded stable-debt components, and the Guardian restored the affected V3 deployments on November 12. Aave V2 Ethereum was unpaused on November 13, while the final remaining restriction—CRV on V3 Polygon—was removed on November 16. These later milestones clarify the resolution but were not knowable when the incident was first disclosed on November 4.

Primary sourceAave Governance Forum — Aave V2/V3 security incident 04/11/2023

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.