SlowMist: Aave v3 Loop Safe Module Exploited, Approximately 114.09 ETH Stolen
SlowMist issued a security alert stating that Aave v3 Loop Safe Module was exploited through an access-control vulnerability in FlashLoopAdapter’s open() and close() functions. The attacker allegedly bypassed Safe authorization and executed arbitrary modules to steal approximately 114.09 ETH from two Safe multisig addresses, while repaying around 1,300 WETH in debt to unlock collateral.
Aave founder Stani Kulechov posted that the incident did not involve Aave v3 contracts, but rather a third-party external adapter built on top of Aave, with no impact on Aave v3. — link
Post #56753
251