Security

Aave V3 Loop Safe Module Exploited for about 114 ETH Through Access Control Flaw

A security alert from SlowMist’s incident listing says an Aave v3-related Loop Safe module called FlashLoopAdapter was exploited in a way that allowed an attacker to drain about 114.09 ETH. The incident appears tied to an access-control weakness in the module rather than to Aave’s core pools.

According to the alert and a later security post from ExVul, the problem was in the module’s authorization check. The adapter reportedly relied on ISafe(msg.sender).isModuleEnabled(address(this)), a condition that could be spoofed by a fake Safe returning a false positive. That allowed arbitrary module execution inside the flow used by the Loop Safe setup.

How the attack was described

ExVul said the attacker used a spoofed Safe to bypass the module check, then executed the drain in a single transaction through a Morpho flash loan. The post said the funds came from two victim Safes and identified the attacker wallet, the vulnerable module contract and the victim addresses.

The security post also said the exploit path involved FlashLoopAdapter’s open() and close() functions, which were meant to manage looping activity without requiring a fresh owner signature each time. In this case, that convenience layer became the exposure point.

The reported loss was roughly 114.092 ETH. ExVul said Aave v3 itself was unaffected and recommended disabling the module.

The incident highlights a familiar DeFi risk pattern: the core protocol may remain intact while a connected module or wrapper contract creates the opening for loss. Here, the reported issue was not with Aave’s lending mechanics, but with the authorization logic used by the Safe module built around them.