Aave FlashLoopAdapter exploit drains 114.09 ETH from two Safes
Security & Exploits ·
An access-control flaw in Aave's v3 Loop Safe module let an attacker forge Safe authentication and drain funds from two multisig wallets.
The exploit targeted Aave's v3 FlashLoopAdapter, a Safe module used in looped lending positions, with losses totaling approximately 114.09 ETH, according to an alert flagged on x.com. Two victim Safe wallets were affected, and the vulnerable contract has been identified on-chain.
The root cause traces to the adapter's open() and close() functions, which checked only whether a calling address reported itself as an enabled module via ISafe(msg.sender).isModuleEnabled(address(this)). That check could be spoofed with a fake Safe contract engineered to always return true. Once authenticated, the adapter's internal swap function executed a router call with parameters fully controlled by the caller. Because the real adapter was registered as an enabled module on the victim Safes, the attacker set the router address to the victim Safe itself and crafted calldata invoking execTransactionFromModule, allowing arbitrary execution against the wallets.
Using this path, the attacker repaid roughly 1,300 WETH in debt to unlock collateral before extracting weETH and Aave collateral held by the two Safes. The exploit transaction is recorded on Etherscan, and an attacker address along with the vulnerable contract address have been published alongside the incident details.
Coverage of the exploit also appeared via wublockchain.xyz, which corroborates the core mechanics of the access-control bypass and the approximate 114 ETH loss figure. Two distinct sources have now reported on the incident, aligning on the vulnerability's root cause and the scale of funds affected.
Unresolved at this stage is whether Aave or the Safe module's maintainers have issued a patch, whether additional Safes using the same FlashLoopAdapter configuration remain exposed, and whether any portion of the stolen ETH has been recovered or frozen. The attacker's wallet has not been reported as sanctioned or linked to further movement of funds at this time.