Skip to content
Back to Guavy Wire
Crypto

Aave v3 Loop Safe Exploit Drains $114,000 Worth of ETH from Multisig Wallets

Instruments
ETH AAVE GNO DAO
Share

A recent exploit on the Aave v3 protocol has drained around $114,000 worth of Ether (ETH) from two multisig wallets using Gnosis Safe. According to SlowMist's threat intel report, the issue lies in the FlashLoopAdapter, an intermediary that automates leverage looping on Aave v3 for Safes looking to amplify yields.

The adapter's open() and close() functions were protected by ISafe(msg.sender).isModuleEnabled(address(this)), but this was spoofable as an attacker can deploy a malicious Safe that unconditionally returns true. Once past the gate, the attacker called using a router address and calldata entirely controlled by the attacker.

The Aave v3 Loop Safe Exploit is not a flaw in Safe's core contracts, which remain widely audited and used by institutions, DAOs, and custodians, but rather in custom module logic authorized by owners. This incident highlights the tension between automation and security in DeFi, particularly with the increasing use of third-party integrated adapters and looping strategies that can introduce outside risk.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc