Todayan hour ago
Project update
Aave V3 Loop Safe Module Exploit Drains $114K in ETH
Aave V3’s Loop Safe Module was exploited, with losses of about 114.09 ETH across two Safe multisigs. The attacker reportedly repaid roughly 1,300 WETH in debt to unlock and withdraw collateral.
SlowMist says the attacker spoofed Safe authentication with a fake Safe that returned true when asked whether the module was enabled. The vulnerable adapter then made an unrestricted call using attacker-controlled router and calldata, allowing the attacker to execute transactions through the victim Safes and drain WETH and Aave collateral.
The reported attacker address is 0x42c2…F9353. The vulnerable contract is 0x16bb…283d8.
Partner Offers | Get Your Instant BTC Cashback | Your Gateway To Crypto | Arcus Private Whitelist