Press Enter to search · ESC to close

DeFi

Aave v3 Loop Safe Module Exploit Drains 114 ETH From Two Safes via Access Control Flaw

An access control flaw in the Aave v3 Loop Safe Module let an attacker spoof a Safe identity and hijack module execution, draining about 114.09 ETH from two multisig wallets. The exploit also abused an unconstrained swap router to unwind roughly 1,300 WETH of debt and free up collateral.

Aave v3 Loop Safe Module Exploit Drains 114 ETH From Two Safes

Two Safe multisig wallets lost roughly 114.09 ETH after an access control vulnerability in the Aave v3 Loop Safe Module was exploited. The flaw allowed an attacker to bypass the module’s permission checks entirely and route a victim Safe’s own execution authority against it.

How the Attack Worked

SlowMist traced the root cause to the FlashLoopAdapter contract. Its open() and close() functions relied on an access control mechanism that could be spoofed by a forged Safe, letting an unauthorized caller trigger module execution. Compounding the problem, the adapter’s _swap() function accepted a fully attacker-controlled router address and arbitrary calldata, giving the exploiter complete control over how funds were routed once inside the call.

  • Bypass: Fake Safe identity defeated the module’s caller verification.
  • Execution: The attacker invoked the victim Safe’s module execution function.
  • Drain: weETH and Aave collateral positions were moved out.
  • Unlock: Roughly 1,300 WETH of debt was repaid to free the pledged collateral.

The debt repayment step is notable: rather than simply extracting loose tokens, the attacker closed out the leveraged loop position, repaid the outstanding WETH borrow, and released the collateral before sweeping it. That sequence suggests a deliberate, well-understood playbook targeting looped positions rather than an opportunistic smash-and-grab.

Why Loop Modules Are a Growing Attack Surface

Looping strategies — repeatedly supplying collateral and borrowing against it to amplify yield — have become one of the most popular ways to farm Aave v3. To make that process seamless, third-party teams build “safe modules” that let a multisig automate the open/close cycle. That convenience concentrates risk: the module holds execution rights over a user’s Safe, so any weakness in its permission model is effectively a weakness in the vault itself.

This incident also highlights a recurring DeFi design anti-pattern: passing user- or caller-supplied addresses into a swap router without an allowlist. When the router is arbitrary and calldata is unconstrained, a single access-control slip becomes a full asset-drain primitive. The 114 ETH loss is small in absolute terms, but the mechanism is not — the same pattern, applied to a larger Safe, would be far more costly.

What Comes Next

Expect module developers to move toward stricter caller attestation, router allowlists, and calldata validation, and toward time-locks or per-transaction caps on automated loop execution. Safe users running third-party modules should treat module permissions as equivalent to signing authority and audit them accordingly. For the broader Aave ecosystem, the core protocol was not implicated — but the adjacent tooling layer now looks like the softest target in the leveraged-yield stack.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback