Aave V3 Loop Safe Exploit Drains 114 ETH, Highlights Risks of Smart Contract Composability
A recent exploit on the Aave v3 Loop Safe module has drained approximately 114.09 ETH, highlighting the risks associated with smart contract composability.
The attack, which occurred on October 2, targeted two Gnosis Safe multisigs using Aave v3 through a Loop Safe Module. The vulnerability was attributed to the FlashLoopAdapter's open() and close() functions, which were protected by ISafe(msg.sender).isModuleEnabled(address(this)).
SlowMist reported that this access control was spoofable, allowing an attacker to deploy a malicious Safe that unconditionally returns true. Once past the gate, the attacker called using a router address and calldata entirely controlled by the attacker.
The Aave v3 Loop Safe Exploit is not a flaw in Safe's core contracts, which remain widely audited and used by institutions, DAOs, and custodians. Instead, the vulnerability lies in custom module logic authorized by owners.
Similar module-authorisation exploits have occurred in the past, with another Safe user losing Rs78 million dollars in rsETH when custom Uniswap v4 Safe modules forwarded caller-supplied calldata into execTransactionFromModuleReturnData across multiple layers.
Security firms, including SlowMist, Blockaid, BlockSec, and AstraSec, have described the exploit as an owner-authorized component failure, rather than a core Safe vulnerability. The incident highlights the tension between automation and security in DeFi.