Aave v3 Loop Safe Module Breach Drains 114 ETH From Two Safe Multisigs

AI مارکیٹ کا خلاصہ
SlowMist reports an exploit of the Aave v3 Loop Safe Module, draining ~114.09 ETH from two Safe multisigs. The issue allegedly involves bypassable access control in FlashLoopAdapter open()/close() via a forged Safe and a swap path that granted attackers control over router and calldata, enabling unauthorized module execution, collateral withdrawals, and debt repayment to unlock assets. This raises near-term smart-contract and integration risk for Aave-related flows.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
AAVE/USDT+9.53%
AI تجزیاتی سمجھ · AAVE/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
SlowMist Security Team monitoring shows the Aave v3 Loop Safe Module was exploited, leading to total losses of about 114.09 ETH across two Safe multisig wallets. SlowMist said the issue traces to the FlashLoopAdapter’s open()/close() access-control design, which could be bypassed using a forged Safe. The risk was compounded by the _swap() function, which gave an attacker full control over the router and calldata. By chaining these weaknesses, the attacker triggered module execution within the victims’ Safes, withdrew weETH and Aave collateral assets, and repaid roughly 1,300 WETH of debt to release the related collateral.