Aave Loop Module Hackers Drain 114.09 ETH from Safe Multisig Wallets
A vulnerability in the Aave loop module allowed hackers to drain 114.09 ETH from two Safe multisig wallets on October 1, 2026. The attack bypassed access control in the FlashLoopAdapter, a helper contract used for leveraged staking. The attackers used a forged Safe contract to trick the adapter's open and close functions, and then exploited a second weakness in the internal _swap function to redirect a swap into an arbitrary transfer.
The hackers financed the operation with a flash loan of 11,537 WETH from Morpho, worth around $31 million at the time. They repaid the loan and made a profit of 114.09 ETH, worth around $307,065. The attack highlights the risks associated with using external contracts in Safe multisig wallets.
Aave's core pools and the Safe core were not affected by the attack, as the vulnerability was specific to the FlashLoopAdapter contract. The incident serves as a reminder to Safe wallet users to regularly inspect their module list and remove any unnecessary modules to prevent similar attacks in the future.