Aave v3 exploit drains up to $310K after Safe module attack

Share

An attacker drained two Safe multisig wallets on Ethereum on October 1, 2026 by exploiting a third-party module called FlashLoopAdapter, designed to run leveraged positions on Aave v3. The attacker forged Safe authentication to repay approximately 1,300 to 1,335 WETH of Aave debt and unlock the victims’ collateral. Combined losses are estimated between $305K and $310K, with a net profit of roughly 114.09 ETH after repaying the flash loan sourced from Morpho. Neither Aave v3 nor Safe’s core infrastructure was compromised; the flaw resided entirely in the FlashLoopAdapter module, whose open() and close() functions poorly validated caller-supplied responses.

Source: Read the original article

Disclaimer: this content is for information purposes only and is not financial advice. Cryptocurrencies are highly volatile: you may lose all of your capital. Always do your own research. Legal notice
Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Read More

Items