Aave V3 Module Security Flaw Allows $305,000 Heist
A security flaw in the Aave V3 Loop Safe Module allowed an attacker to bypass Safe wallet authorization and drain approximately $305,000 in crypto from two multisignature wallets.
According to SlowMist, a blockchain security firm, the attacker exploited two weaknesses in the system.
The first was an access-control flaw in the FlashLoopAdapter, a module designed to manage leveraged Aave V3 positions through Safe wallets.
The vulnerability allowed the attacker to bypass Safe's authorization checks and run unauthorized modules.
The attacker created a fake Safe contract that passed the module's checks, tricking the system into treating it as a legitimate wallet.
The second weakness involved the contract's handling of swaps, giving the caller too much control over where instructions were sent and what those instructions contained.
The entire attack happened in a single transaction, starting with a WETH flash loan from Morpho.
The attacker used the borrowed funds to repay roughly 1,300 WETH in Aave debt held by the wallets, unlocking the collateral securing those loans, which the attacker then withdrew.
About 114.09 ETH, worth around $305,000 at the time of the incident, was stolen from two Safe multisig wallets.