SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen
In Brief
SlowMist reports an Aave v3 Loop Safe module exploit that drained 114 ETH via a spoofable access control flaw; the core Aave protocol remains unaffected.

Blockchain security firm SlowMist has issued an alert after the Aave v3 Loop Safe module was exploited through an access-control vulnerability, resulting in the loss of approximately 114.09 ETH (around $305,000) from two Safe multisignature wallets. The attack, detected on October 1 by Defimon Alerts, targeted the FlashLoopAdapter contract but left the core Aave v3 protocol untouched.
FlashLoopAdapter is a Safe module designed to automate the opening and closing of leveraged positions on Aave v3. According to SlowMist, the root cause of the exploit lay in the access controls of the adapter’s `open()` and `close()` functions. Rather than independently verifying the caller’s identity, the functions merely checked that `ISafe(msg.sender).isModuleEnabled(address(this))` returned true. An attacker could therefore deploy a fake Safe contract programmed to always return true, allowing the malicious caller to pass the verification check.
The attacker then exploited the module’s `_swap()` function, which executes a raw call to a caller-supplied router with fully attacker-controlled calldata. By setting the router to a victim Safe address and the calldata to `execTransactionFromModule` — a Safe function that lets an enabled module execute transactions — the attacker effectively turned the adapter’s own permissions into a remote control over the victims’ wallets. Because FlashLoopAdapter was already enabled as a module on both targeted Safes, the resulting calls were accepted without issue.
The attack chain involved more than simply draining available balances. The attacker took a Morpho WETH flash loan and used the borrowed funds to repay approximately 1,335 WETH of Aave debt belonging to the larger wallet, identified as 0xcfedf95a3653a128dfc2e4288758a1a1850d169f.
Repaying the debt unlocked the leveraged position’s collateral, after which the attacker had the Safe withdraw roughly 1,306 weETH to an attacker-controlled address. A second Safe, 0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520, lost an additional 6.4 weETH through the same mechanism. Defimon Alerts noted that both wallets shared the same single owner. After settling the flash loan and converting part of the withdrawn collateral to WETH, the attacker retained around 114.1 ETH. The attacker address was identified as 0x42c2633438609881c8fBAb82414eb9A0c45F9353, while the vulnerable contract sits at 0x16bb8b912da187870c23ec6756bb3fad061283d8.
Aave v3 core unaffected, echoing earlier Safe module incidents
In response to the incident, Aave founder and CEO Stani Kulechov clarified in a post that the exploited code was not part of Aave v3 itself but a third-party external adapter built on top of the protocol, with zero effect on the core contracts. Neither security alert identified any vulnerability in Aave v3, which continued to operate normally.
The exploit nonetheless highlights a recurring pattern in the Safe ecosystem. Because modules are granted the ability to execute transactions from a wallet without going through the standard owner approval flow, a single flaw in a module’s authentication logic can expose all assets under its control. A similar weakness surfaced in September, when an Ethereum Safe exploit involving roughly 2,900 rsETH was traced to inadequate authorization checks in an executor contract tied to an enabled module. In May, attackers drained approximately $3 million from 86 wallets by abusing the SquidRouterModule, and Gnosis Pay users were separately urged to withdraw funds after a flaw was found in its Zodiac delay module.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



