Aave v3 Loop Safe Module Hacked, 114 ETH Stolen
Aave's v3 Loop Safe module has been hacked, with the attacker exploiting an access control vulnerability in the FlashLoopAdapter's open()/close() functions.
The attacker forged Safe authentication and executed arbitrary modules to steal approximately 114.09 ETH from two Safe multisig addresses and repay approximately 1,300 WETH in debt to unlock collateral.
The attack was reported by SlowMist on social media, with the incident occurring on October 2.
The Aave v3 Loop Safe module is a feature that allows users to borrow and lend assets in a decentralized manner.