SlowMist reported a hack of the Loop Safe module, which is used for looping positions in Aave v3âessentially, repeatedly borrowing against collateral to increase position size. The attacker withdrew approximately 114 ETH from two multisig Safe wallets.
The vulnerability lay in the FlashLoopAdapter contract. The access check merely asked the calling wallet whether the module was enabled, and the attacker substituted a fake Safe wallet that always responded âyes.â The contract then executed an arbitrary call with the attackerâs parameters. Since the adapter was connected as a module to the victimsâ wallets, the hacker withdrew weETH and collateral from Aave on their behalf, first paying off about 1,300 WETH of debt to unlock the collateral.
The Aave protocol itself, according to the description, was not affected; the issue lies in the third-party module.