Mars financial news,
HyperEVM native decentralized lending protocol HypurrFi
published on platform X stating that Aave V3 version 3.5 and earlier has a "rounding error" vulnerability,
under specific conditions, an attacker could extract underlying tokens by repeatedly executing supply/extract and borrow/repay cyclical operations.
The affected markets are XAUT0 and UBTC in HypurrFi Pooled. Currently, user funds are not at risk; to ensure safety, related markets have suspended new supply and lending operations, while withdrawal and repayment functions remain operational, and other markets are functioning normally. HypurrFi further stated that it quickly identified the issue on-chain through its internal monitoring system and timely froze the affected markets, while collaborating with other Aave deployers and security researchers to address the matter, and inviting other Aave fork projects to reach out for more security information.
#AAVE #uBTC #HyperEVM $XAU
$BTC $ETH