Aave V3 Loop Safe Module Exploited via Access-Control Vulnerability; 114.09 ETH Stolen
AI Market Summary
SlowMist reports an access-control exploit in the Aave V3 Loop Safe Module, where a spoofed Safe allegedly bypassed module authorization in FlashLoopAdapter's open()/close() logic. Roughly 114.09 ETH was reportedly stolen from two Safe multisig addresses after arbitrary modules were executed to access protected funds, with debt repayment used to unlock collateral. The incident raises near-term protocol integration and smart-contract risk concerns around Aave-related tooling.
Impact level
● Medium
Affected assets
AAVE/USDT+9.78%
AI Insight · AAVE/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
According to a report by blockchain security firm SlowMist, the Aave V3 Loop Safe Module has been exploited due to a critical access-control vulnerability within the FlashLoopAdapter's open() and close() functions. The attacker successfully circumvented Safe authorization protocols by spoofing checks intended to verify module permissions, enabling the execution of arbitrary modules to access protected funds. This exploit resulted in the theft of approximately 114.09 ETH from two Safe multisig addresses. SlowMist further noted that the perpetrator repaid nearly 1,300 WETH in debt to unlock the underlying collateral. The security firm's technical analysis revealed that the access-control logic relied solely on verifying the sender's module status, a condition easily manipulated by a malicious contract. This flaw allowed unauthorized internal calls, including the _swap() function, to proceed, compromising the integrity of the multisig addresses.