Aave V3 Module Exploit Drains $310K from Two Ethereum Wallets
An attacker drained two Ethereum wallets on October 1, exploiting a third-party module built for Aave v3. Security firm SlowMist flagged the attack, which resulted in estimated losses of between $305K and $310K. The exploiter forged Safe authentication to gain access to the wallets' collateral, repaying about 1,300 WETH of Aave debt to unlock the collateral.
The vulnerable component was the FlashLoopAdapter, a module designed to help users build leveraged positions on Aave v3. The attacker deployed a fake contract that impersonated Safe authentication, allowing them to steer the module's execution paths to move assets out of the wallets. The operation was run in a single transaction, starting with a WETH flash loan sourced from Morpho.
Post-incident analyses traced the flaw to the module's open() and close() functions, which had weak validation of responses controlled by the caller. The module accepted answers from whoever called it without properly confirming they came from a legitimate Safe. SlowMist and fellow security firm ExVul both raised alerts after the attack, and the affected Safes disabled the vulnerable module right away to stop further losses.