SlowMist issued a security alert stating that Aave v3 Loop’s Safe Module was exploited through an access control vulnerability in FlashLoopAdapter’s open() and close() functions. The attacker
SlowMist issued a security alert stating that Aave v3 Loop’s Safe Module was exploited through an access control vulnerability in FlashLoopAdapter’s open() and close() functions.
The attacker allegedly bypassed Safe authorization and executed arbitrary modules to steal approximately 114.09 ETH from two Safe multisig addresses, while repaying around 1,300 WETH in debt to unlock collateral.
Users question the module’s access controls and safety
The warning from SlowMist quickly drew attention to both the scope of the exploit and how the vulnerable module allowed the attack to happen. Aave founder and CEO Stani Kulechov first clarified that the incident did not involve Aave V3 itself, but a third-party adapter built on top of the protocol. He said users who had enabled the module on their Safe should disable it until it is fixed.
DMX then focused on the module’s security, saying the access control on its “open()” and “close()” functions was weak. SlowMist’s warning said attackers were able to bypass those checks and use the module to drain assets from two Safe wallets.
USDT raised a different concern: what happens to the stolen funds after the attack. The user said the funds could be split and swapped quickly, warning stablecoin holders and P2P desks to watch for payments from new wallets and check the source of the money before releasing funds.
Also Read: Aave Hits $1B as Mantle TVL Surges on ZK and Tokenized Stocks
Aave’s pattern of losses keeps coming from adapters, bridges and modules
In August 2024, a vulnerability in Aave’s Repay With Collateral Adapter, a peripheral contract used only on the app.aave.com interface, let an attacker drain about 56,000 dollars across several chains.
Aave confirmed at the time that the adapter had no relation to its core pool contracts and that no user funds involved in actual lending positions were at risk. In April 2026, a vulnerability in aLayerZero bridge let an attacker mint 116,500 fake rsETH tokens and deposit them as collateral on Aave v3, triggering roughly 230 to 300 million dollars in bad debt and a bank run that pulled more than 30% of Aave’s deposit base within four days. Aave’s own incident report stated plainly that its smart contracts were not compromised at any point; the fault sat entirely in KelpDAO’s bridge.
Now, with today’s Loop Safe Module exploit, the same pattern repeats a third time, a loss attached to the Aave name, traced back to code Aave didn’t write and doesn’t control.
Safe wallet modules have become 2026’s most repeated attack pattern
In May, a vulnerability in a third-party add-on called SquidRouterModule let an attacker impersonate authorized delegates and drain about 3.2 million dollars from 86 Gnosis Safe wallets across Ethereum and Base in roughly two hours.
Safe Labs CEO Rahul Rumalla said at the time that the affected accounts “do not seem to be operated on official Safe Wallet products,” and pointed to a built-in feature called Safe Shield, designed specifically to flag unverified modules before users grant them permission.
Days later, on June 1, Gnosis Pay suffered a separate exploit targeting its Delay Module, a component controlling transaction permissions on user Safe wallets, and pledged to cover user losses. In a separate case, an attacker drained 7.8 million dollars in rsETH from a Safe wallet through a Multicall helper that treated any call pointing back at its own address as pre-approved, letting outside instructions run as if the wallet itself had authorized them, before a bot watching the same block stole the stolen funds right back from the attacker.
Security researchers at Blockaid described that incident as “module authorization abuse on that Safe, not a Safe core or owner key bug,” the exact same distinction Aave is drawing today. Four module-based exploits in roughly five months, each pinned on a trusted but unaudited add-on rather than Safe’s own contracts, make today’s Loop incident look less like an isolated bug and more like the latest entry in an attack pattern DeFi still hasn’t closed off.
What happens next for Aave users
There have been no confirmed CEX deposits, freezes, reimbursements, or global module revocation. The focus now turns to whether other Safe wallets are exposed to the same FlashLoopAdapter flaw. Security teams will need to check how widely the module was used and whether other wallets could face a similar attack.
The vulnerable module will also come under review. Developers will have to decide whether to disable it, replace it, or release a fix before users can safely use it again.
Meanwhile, Aave has officially gone live on the Solana blockchain through an integration powered by Sunrise. The deployment allows Solana users to supply assets to earn interest or borrow against collateral, marking a significant expansion of Aave’s multi-chain footprint into one of the industry’s most active Layer-1 ecosystems.
Enjoyed this? BookmarkDeFi Planet, explore related topics, and follow us onTwitter,LinkedIn,Facebook,Instagram,Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.
The post SlowMist Flags a 114 ETH Theft From Aave v3 Loop’s Safe Module appeared first on DeFi Planet.