Aave Module Exploited for $305,000 Wallet Heist
An attacker exploited a vulnerability in Aave V3's Loop Safe Module to drain around $305,000 from two multisignature wallets. The module is used to manage leveraged Aave V3 positions through Safe wallets.
The attack relied on weaknesses in the module's access-control and swap functionality, allowing the attacker to bypass authorization checks and run unauthorized modules.
Aave has not issued a public response or statement regarding the incident. There is no confirmed fix, shutdown, or compensation plan at this time.