A security flaw in a module linked to Aave V3 enabled an attacker to bypass Safe wallet authorization and drain roughly $305,000 in cryptocurrency from two multisignature wallets.
Blockchain security firm SlowMist issued a security alert concerning an exploit targeting Aave V3’s Loop Safe Module.
Aave V3 Module Exploit
According to SlowMist, the attacker leveraged two vulnerabilities. The first was an access‑control flaw in the FlashLoopAdapter, a module designed to manage leveraged Aave V3 positions through Safe wallets.
SlowMist TI Alert
@aave v3 Loop Safe Module Loss: ~114.09 ETH
Root Cause: FlashLoopAdapter’s open()/close() access control only checks ISafe(msg.sender).isModuleEnabled(address(this)), which is spoofable via a fake Safe that always returns true. Its _swap() then…
— SlowMist (@SlowMist_Team) October 2, 2026
The vulnerability reportedly allowed the attacker to circumvent Safe’s authorization checks and run unauthorized modules. By creating a counterfeit Safe contract that passed the module’s verification, the attacker tricked the system into treating it as a legitimate wallet. In effect, the system merely asked whether the wallet claimed to trust the contract, enabling the attacker to craft a fake Safe that always answered “yes.”
How the Safe Wallet Attack Worked
The second weakness pertained to the contract’s swap handling, granting the caller excessive control over both the destination of instructions and their content.
The attacker exploited this to direct the victims’ own Safe wallets to transfer funds. Because the compromised module was already trusted by the victims’ wallets, the wallets executed the malicious instructions.
The entire breach occurred in a single transaction, initiated with a WETH flash loan from Morpho. The attacker used the borrowed funds to repay approximately 1,300 WETH of Aave debt held by the wallets. Settling the debt released the collateral securing those loans, which the attacker then withdrew.
SlowMist reported that roughly 114.09 ETH—valued at about $305,000 at the time—was siphoned from two Safe multisig wallets.
Two Safe Wallets Were Drained
The incident involved two Safe multisig wallets that utilized the vulnerable module. The exploit hinged on flaws in the module’s access‑control and swap functionality.
No evidence suggests that funds deposited directly into Aave were compromised.
Aave Has Not Issued a Public Response
Neither the Aave protocol nor the module’s developers have released an official statement regarding the breach.
There is currently no confirmed fix, shutdown, or compensation plan in place. Aave has also not published an official loss breakdown or security advisory.
Why Safe Modules Can Create Security Risks
Safe wallets are modular, enabling users to integrate tools that automate strategies or connect to protocols like Aave. However, modules that have permission to move funds can introduce new security risks; if a module contains a flaw, a wallet’s standard multisig safeguards may fail to prevent an unauthorized transaction.
Why This Matters
The event demonstrates that a vulnerability in a third‑party module can bypass the protections of a Safe wallet that has already authorized it. It also underscores that users’ exposure may depend on the specific modules and integrations linked to their wallets, not solely on the underlying Aave protocol.
Also Read
- Deadlock’s City Never Sleeps Update Sparks a Surge: 6 New Heroes and a Record Player Count
- Arbitrum Security Council Halts New Stylus Activations Amid AI-Assisted Attack Concerns
- Plunging GPU prices threaten AI hosts, and new hedges step in
- USD/CAD Outlook: Upside Bias Persists, Targeting 1.4497, While a Break Below 1.4153 Signals Deeper Pullback


