Aave v3 Loop Module Hacked for 114 ETH in Exploit of FlashLoopAdapter
A hack on the Aave v3 Loop Module resulted in a loss of approximately 114.09 ETH, worth around $307,065 at the time of the transaction, from two Safe multisig wallets. The attack exploited the FlashLoopAdapter contract, which enables the loop of positions on Aave v3. The attacker used a flash loan from Morpho, worth around $31 million, to fund the operation.
According to SlowMist, the root cause of the vulnerability lies in the access control check of the FlashLoopAdapter contract, which only verifies that the caller is an enabled module. A contract can spoof this check by always returning true, allowing the adapter to access the Safe's assets. The adapter then used the Safe's module-execution function to execute the swap path, taking a router and calldata from the caller.
The two victim Safes recorded a successful module execution, naming the adapter at 0x16bb8b912da187870c23ec6756bb3fad061283d8. Aave's pool logged a repayment of 1,335.26 WETH, retiring 1,329.54 of variable debt and releasing 1,306.48 weETH worth around $3.9 million. The attacker's contract received 114.096151469674448809 ETH, and the operation was funded by an 11,537 WETH flash loan from Morpho, about $31 million, repaid within the same transaction.
Aave has not commented on the incident, and it is not clear whether other Safes that had the FlashLoopAdapter enabled are also affected. The protocol's pools were used in the attack, but the loss is attributed to the module's caller check vulnerability.