Aave v3 Loop Safe Exploit: 114 ETH Loss in $30B Protocol

Add as a preferred source on Google

SlowMist flagged a 114 ETH exploit on Aave v3 Loop Safes after FlashLoopAdapter's spoofable isModuleEnabled check was abused. Attacker drained two multisigs via arbitrary execTransactionFromModule calls after repaying 1300 WETH debt, exposing systemic risk in third-party Safe modules beyond core protocol security.

Aave v3 Loop Safe exploit draining 114ETH has again put the spotlight on ongoing threats to smart contract composability, with security firm SlowMist citing a spoofable access control that allowed an attacker to drain collateral from multisigs. On Oct 2, Mist published a threat intel report citing losses from two Gnosis Safe multisigs using Aave v3 through a Loop Safe Module.

As per the Etherscan transaction, an attacker drained ~114.09 ETH after repaying about 1300 WETH in debt to unlock collateral, causing losses to the vulnerable contract at the heart of the investigation.

How FlashLoopAdapter Access Control Went

The cause of the Aave v3 Loop Safe Exploit is embedded in FlashLoopAdapter, an intermediary automating leverage looping on Aave v3 for Safes who want to amplify their yields. Its open() and close() functions were protected by ISafe(msg.sender).isModuleEnabled(address(this)). SlowMist reported that this was spoofable, as an attacker can deploy a malicious Safe that unconditionally returns true.

Aave

Source: aave.com

Once past the gate in the Aave v3 Loop Safe Exploit, the attacker called using a router address and calldata entirely controlled by the attacker. Since the adapter was already an enabled module on the victim Safes, the attacker set the router to the victim Safe itself and crafted data as execTransactionFromModule to tell the Safe to send weETH and Aave collateral directly to the attacker.

This pattern shows the Aave v3 Loop Safe Exploit is not a flaw in Safe’s core contracts, which remain widely audited and used by institutions, DAOs, and custodians, but in custom module logic authorized by owners.

Also Read: Aave V4 Monad Proposal Adds Utility as AAVE Price Holds Above Key Level

Why Still Systemic Risks with Module Vulnerabilities

This incident is part of an increasing pattern of module-authorisation exploits, which have wrecked smart wallets in 2023. According to Blockaid in September, another Safe user lost Rs78 million dollars in rsETH when custom Uniswap v4 Safe modules forwarded caller-supplied calldata into execTransactionFromModuleReturnData across multiple layers, completely evading signature checking.

Multiple security firms, Blockaid, BlockSec, AstraSec, and SlowMist, described that earlier exploit as an owner-authorized component failure, rather than a core Safe vulnerability. For wider DeFi, the Aave v3 Loop Safe Exploit and similar attacks exemplify the tension between automation and security.

DeFi

Source: LinkedIn

According to DefiLlama, Aave v3 secures over $30 billion in total value locked across Ethereum, Arbitrum, Optimism, and Base, and the Aave v3 Loop Safe Exploit shows how it depends on third-party integrated adapters and looping strategies that can introduce outside risk.

Leveraging looping to increase yields on liquid restaked tokens like weETH, rsETH and eETH needs additional god-mode smart contract security beyond Aave itself, and the Aave v3 Loop Safe Exploit highlights the impact on institutions using multisig custody, DAO treasuries and funds that rely on Safe for transaction security.

Also Read: AAVE Price Eyes Breakout as Rising Protocol Activity Strengthens Outlook

Industry Implications and What Happens Next

For affected users of the Aave v3 Loop Safe Exploit, there is no effective path to recovery without direct negotiation or white-hat assistance, given the irreversibility of Ethereum transactions. The event will cause audit firms and Safe ecosystem curators to double down on analysis of module marketplaces.

Programmers implementing on Aave v3 and other lending protocols (e.g., Compound, Spark, and Morpho) will probably review the method to check that msg. Sender isn’t a contract and establish more comprehensive allowlists again.

Aave v3 Loop Safe Exploit

Source: LinkedIn

From an institutional angle, with both core protocol logic and sender verification, the risk in smart contracts has now shifted to peripheral automation layers. Risk managers like Chaos Labs or Gauntlet, insurers, and incident-locating companies like Forta, Blockaid, and SlowMist, should increase coverage on module-level calls.

SlowMist

Client asset-safe institutions using Safe will likely require a formal audit for approved modules – soon, a ‘zero trust module strategy’ and preceding simulation of transaction preview via Safe arrangements should be pushed forward to sustain enterprise confidence and code’s composability.

Also Read: Aave Price Eyes Strong Recovery to $400 as DeFi Activity Strengthens

Ananthyka J

Ananthyka J

Ananthyka J is a market reporter at Tronweekly, reporting on cryptocurrency news. She covers cryptocurrency markets, blockchain technology, and digital asset regulation, focusing on Bitcoin, Ethereum, DeFi, altcoins, and crypto policy. Her reporting emphasizes clear and accurate market coverage, including crypto market movements, regulatory developments, and blockchain adoption. She holds a BA in Journalism and Mass Communication and an MA in Communication and Media Studies. She has also completed multiple media internships, follows strict editorial and fact-checking standards, and discloses potential conflicts of interest when reporting.

Articles: 834