DropsTab logo - blue line depicting the shape of a water drop with Christmas decoration
M. Cap: $2.91 T 0.47%24h Vol: $66.97 B −60.38%BTC: $84,909.00 0.29%ETH: $2,694.26 0.63%S&P 500: $7,723.65 0.00%Gold: $4,141.79 0.00%BTC Dominance: 58.60%

About 114 ETH was withdrawn from two Safe multisigs via the Aave (AAVE) v3 looping module.

02 Oct, 2026byDropsTab
Join Our Socials

SlowMist reported a hack of the Loop Safe module, which is used for looping positions in Aave v3—essentially, repeatedly borrowing against collateral to increase position size. The attacker withdrew approximately 114 ETH from two multisig Safe wallets.

The vulnerability lay in the FlashLoopAdapter contract. The access check merely asked the calling wallet whether the module was enabled, and the attacker substituted a fake Safe wallet that always responded “yes.” The contract then executed an arbitrary call with the attacker’s parameters. Since the adapter was connected as a module to the victims’ wallets, the hacker withdrew weETH and collateral from Aave on their behalf, first paying off about 1,300 WETH of debt to unlock the collateral.

The Aave protocol itself, according to the description, was not affected; the issue lies in the third-party module.

Continue reading this article on source: x.com