Aave v3 Loop Safe Module Exploit: 114.09 ETH Stolen
A security exploit targeting a third-party Aave v3 Loop Safe module drained approximately 114. 09 ETH on October 1, 2026, with blockchain data confirming a precise transfer of 114.
A security exploit targeting a third-party Aave v3 Loop Safe module drained approximately 114.09 ETH on October 1, 2026, with blockchain data confirming a precise transfer of 114.096151469674448809 ETH valued at $308,696.27 at the time of transfer. Blockchain security firm SlowMist issued the alert, identifying the vulnerable component as FlashLoopAdapter, a custom Safe module built around Aave V3’s lending infrastructure.
What SlowMist Reported About the Aave v3 Loop Safe Module Exploit
SlowMist’s security alert attributed the flaw to authorization logic in FlashLoopAdapter’s open() and close() functions, which relied on ISafe(msg.sender).isModuleEnabled(address(this)) to verify callers. That check can be spoofed by a contract that implements the ISafe interface without being a genuine Safe deployment, allowing an attacker to impersonate the wallet and trigger unauthorized fund movements. For related coverage, see Fintech Revolution Summit –Thailand 2026.
Two Safe multisig wallets were affected, according to The Crypto Times. The on-chain transaction, recorded at 15:08:47 UTC, withdrew 1,306.4823 weETH from Aave and repaid 1,335.2558 WETH to Aave: Ethereum WETH V3, with the net ETH proceeds routed to the address Etherscan labels “Aave V3 Loop Exploiter 1.” For related coverage, see Cyber Revolution Summit Vietnam 2026.
Reported loss: approximately 114.09 ETH
SlowMist’s alert placed the total loss at approximately 114.09 ETH, consistent with the gross transfer figure visible in the confirmed Ethereum transaction.
ON-CHAIN DATA
- Transaction: 0x75328f…616fc4
- Amount transferred: 114.096151469674448809 ETH ($308,696.27 at time of transfer)
- To: Aave V3 Loop Exploiter 1
- weETH withdrawn: 1,306.4823 weETH from Aave
- WETH repaid: 1,335.2558 WETH to Aave: Ethereum WETH V3
- Timestamp: October 1, 2026, 15:08:47 UTC
What the alert identifies, and what it does not yet confirm
SlowMist’s alert names the FlashLoopAdapter module as the attack surface and does not claim that Aave V3 core lending pools were compromised. The exploit targeted wallet-level module logic, not Aave’s supply and borrow contracts. A full post-mortem has not been published as of this report, and the total number of affected wallets beyond the two identified has not been confirmed. For related coverage, see Cyber Revolution Summit Saudi Arabia 2026.
Aave founder Stani Kulechov drew a clear scope boundary in a public statement on X shortly after the alert, a distinction that has direct implications for the broader DeFi trust model Kulechov has been articulating, including his arguments about how DeFi protocols should be evaluated against their peripheral integrations.
This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.
— Stani (@StaniKulechov) October 2, 2026
Source: @StaniKulechov on X
Why Module-Level Security Matters in DeFi Lending Setups
Component risk can differ from core-protocol risk
Safe multisig wallets support modular extensions that interact with DeFi protocols, creating a layer of custom logic between user funds and audited contract code. FlashLoopAdapter operated in that intermediate layer, using Aave V3 as a liquidity backend while managing looped position entry and exit through its own authorization model. As Aave Labs expands its protocol surface, including a tokenized-asset credit market on Avalanche, module-level audit discipline becomes increasingly relevant for any integration that inherits Aave’s trust reputation without undergoing equivalent scrutiny.
The weETH and WETH collateral cycle visible in the transaction data is consistent with leveraged restaking strategies that use loop adapters to amplify yield on liquid staking tokens. Users running similar setups through third-party adapters should verify whether their module authorization paths can be spoofed by a contract that merely implements the ISafe interface rather than being a genuine Safe deployment.
What users and integrators should monitor after an alert
For integrators building on top of Aave V3 with custom Safe modules, the primary check is whether authorization logic validates the calling context against a trusted registry rather than relying on msg.sender self-attestation. SlowMist’s identification of the spoofable isModuleEnabled check points to an authorization pattern that can surface wherever Safe modules delegate trust to the caller’s own reported state. Protocol monitoring tools and wallet-level audit reviews remain the recommended action while the full scope of this incident is investigated.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Defiliban · Oliver Benjamin
Oliver Benjamin
@oliver-benjamin