Aave Loop Module Flaw Allows 114.09 ETH Heist from Safe Multisig Wallets
A flaw in a helper contract used by Aave's loop module allowed an attacker to drain 114.09 ETH from two Safe multisig wallets on October 1, 2026.
The loop module, designed to provide leverage on staking yields, was the entry point for the attack. The contract, called FlashLoopAdapter, was compromised, allowing the attacker to bypass access control and execute transactions without the usual signing quorum.
The attacker, who was able to repay 1,300 WETH of debt and profit from the transaction, used a flash loan of 11,537 WETH to finance the attack. The affected wallets had the loop module enabled, which allowed the attacker to execute the transaction without the usual safeguards.
According to the source, the core pools of Aave v3 and the Safe core contracts themselves were not compromised. The attack was limited to wallets that had enabled the loop module, and those who deposited ether or weETH directly with Aave without using a loop module were not affected.