Aave v3 exploit drains up to $310K after Safe module attack

4 days ago 12



An attacker drained two Safe multisig wallets on Ethereum on October 1, 2026. They did it by exploiting a third-party module built to run leveraged positions on Aave v3. Security firm SlowMist flagged the attack. It reported that the exploiter forged Safe authentication and repaid about 1,300 WETH of Aave debt to unlock the wallets’ collateral. Combined victim losses are estimated between $305K and $310K. Neither Aave v3 nor Safe’s core infrastructure was compromised. The weak link was the FlashLoopAdapter, a module the victims had enabled on their own wallets. How the FlashLoopAdapter attack worked The vulnerable component was the FlashLoopAdapter, a module designed to help users build leveraged positions on Aave v3. It gets limited permission to operate the account so the owner doesn’t have to do every step by hand. The attacker deployed a fake contract that impersonated Safe authentication. That let them slip past the module’s access controls. From there, they steered the module’s execution paths to move assets out of the two multisigs. The whole operation ran in a single transaction. It started with a WETH flash loan sourced from Morpho. With the borrowed funds, the attacker pa...

Read Entire Article