Aave v3 Loop Safe Module Hacked for 114 ETH, Exploiting Open/Close Vulnerability
Aave's v3 Loop Safe module was hacked on October 2, according to SlowMist, as reported by PANews. The attacker exploited an access control vulnerability in the FlashLoopAdapter's open()/close() functions, allowing them to forge Safe authentication and execute arbitrary modules.
The attack resulted in approximately 114.09 ETH being stolen from two Safe multisig addresses, with around $1.3 million worth of WETH (Wrapped Ether) used to repay debt and unlock collateral.