Aave V3 Suffers Loop Module Exploit Worth Over $200K
An exploit targeting Aave V3's Loop Safe Module has drained about 114.09 Ether (ETH) from two Safe multisignature addresses.
The attacker used forged Safe authentication and unauthorized module execution to take the ETH, exploiting access-control flaws in the FlashLoopAdapter contract's open() and close() functions.
About 1,300 wrapped Ether (WETH) in debt was then repaid, allowing collateral to be unlocked. This incident involved the Loop Safe Module and its adapter, which handle looping operations through Aave V3.