Aave v3 Loop Safe Exploit Drains $114,000 Worth of ETH from Multisig Wallets
A recent exploit on the Aave v3 protocol has drained around $114,000 worth of Ether (ETH) from two multisig wallets using Gnosis Safe. According to SlowMist's threat intel report, the issue lies in the FlashLoopAdapter, an intermediary that automates leverage looping on Aave v3 for Safes looking to amplify yields.
The adapter's open() and close() functions were protected by ISafe(msg.sender).isModuleEnabled(address(this)), but this was spoofable as an attacker can deploy a malicious Safe that unconditionally returns true. Once past the gate, the attacker called using a router address and calldata entirely controlled by the attacker.
The Aave v3 Loop Safe Exploit is not a flaw in Safe's core contracts, which remain widely audited and used by institutions, DAOs, and custodians, but rather in custom module logic authorized by owners. This incident highlights the tension between automation and security in DeFi, particularly with the increasing use of third-party integrated adapters and looping strategies that can introduce outside risk.