Aave V3 Loop Safe Module Exploited via Access-Control Vulnerability; 114.09 ETH Stolen

AI مارکیٹ کا خلاصہ
SlowMist reports an access-control exploit in the Aave V3 Loop Safe Module, where a spoofed Safe allegedly bypassed module authorization in FlashLoopAdapter's open()/close() logic. Roughly 114.09 ETH was reportedly stolen from two Safe multisig addresses after arbitrary modules were executed to access protected funds, with debt repayment used to unlock collateral. The incident raises near-term protocol integration and smart-contract risk concerns around Aave-related tooling.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
AAVE/USDT+12.04%
AI تجزیاتی سمجھ · AAVE/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
According to a report by blockchain security firm SlowMist, the Aave V3 Loop Safe Module has been exploited due to a critical access-control vulnerability within the FlashLoopAdapter's open() and close() functions. The attacker successfully circumvented Safe authorization protocols by spoofing checks intended to verify module permissions, enabling the execution of arbitrary modules to access protected funds. This exploit resulted in the theft of approximately 114.09 ETH from two Safe multisig addresses. SlowMist further noted that the perpetrator repaid nearly 1,300 WETH in debt to unlock the underlying collateral. The security firm's technical analysis revealed that the access-control logic relied solely on verifying the sender's module status, a condition easily manipulated by a malicious contract. This flaw allowed unauthorized internal calls, including the _swap() function, to proceed, compromising the integrity of the multisig addresses.