NewsCryptoSlowMist Alert: Aave v3 Loop Safe Module Exploit Drains 114.09 ETH

SlowMist Alert: Aave v3 Loop Safe Module Exploit Drains 114.09 ETH

Author: NFTENEXยท

Key Takeaways

  • โ€ขSlowMist reported that the Aave v3 Loop Safe Module was exploited, with losses estimated at approximately 114.09 ETH.
  • โ€ขThe alert identifies Loop Safe Module, a Safe wallet add-on that automates leveraged looping strategies, as the target rather than the core Aave v3 lending protocol.
  • โ€ขThe attack vector, the number of affected wallets, and whether the vulnerability has been patched have not been confirmed.
  • โ€ขThe 114.09 ETH figure is an initial estimate that may be revised as on-chain forensic analysis progresses.
  • โ€ขSlowMist previously flagged a FlashLoopAdapter flaw tied to Safe Wallet collateral drains, indicating a recurring pattern of module-level exploits.
SlowMist Alert: Aave v3 Loop Safe Module Exploit Drains 114.09 ETH

Blockchain security firm SlowMist has issued an alert reporting that the Aave v3 Loop Safe Module has been exploited, with approximately 114.09 ETH reportedly stolen. The alert specifically identifies the Loop Safe Module as the targeted component, not the Aave v3 protocol as a whole.

SlowMist Identifies Loop Safe Module as Exploit Target

SlowMist, a blockchain security firm that monitors on-chain threats and protocol vulnerabilities, published a security alert naming the Aave v3 Loop Safe Module as the target of the attack. The firm put the estimated loss at approximately 114.09 ETH.

According to the alert, the theft stems from a vulnerability in the Loop Safe Module specifically. That component is distinct from the core Aave v3 lending protocol, and SlowMist does not claim that the broader Aave v3 contracts were compromised. Until an official project communication clarifies the full attack surface, users should treat the module and the underlying protocol as separate scopes.

The incident fits a broader pattern of targeted module-level exploits across DeFi infrastructure. SlowMist previously flagged a FlashLoopAdapter flaw tied to Safe Wallet collateral drains, suggesting that loop-based adapter modules have become a recurring focal point for attackers probing Safe-integrated Aave positions.

Why the Incident Matters for Loop Module Users

The reported loss of approximately 114.09 ETH is concentrated in the Loop Safe Module, a tool that allows users to automate leveraged looping strategies on Aave v3. Positions held through this specific module therefore carry a different risk profile than positions interacted with directly on Aave v3.

Safe modules are add-on contracts that extend the functionality of Safe wallets. In this case, the Loop Safe Module automates the repeated supply-and-borrow cycles that leveraged looping strategies require, executing them on behalf of users rather than requiring each step to be signed manually.

SlowMist's alert does not confirm the attack vector, the number of affected wallets, or whether the vulnerability has been patched. Anyone using the Aave v3 Loop Safe Module should monitor official communications from the relevant project team and consider reviewing open positions until a post-mortem is published.

Incidents that target modular DeFi infrastructure rather than core contracts also highlight the growing complexity of composable smart contract risk. Each additional module in a stack introduces an independent attack surface, meaning security reviews need to extend beyond the primary protocol to every integration layer.

What to Watch Next

Early security alert details frequently change as on-chain investigations progress. The 114.09 ETH figure reported by SlowMist is an initial estimate, and revised loss assessments are common once forensic analysis reconstructs the full sequence of affected transactions on Etherscan or equivalent block explorers.

Key developments to monitor include an official response from the Loop Safe Module project team, any proposed mitigation or contract pause, and whether independent security researchers confirm or revise the scope of the exploit. Protocol teams operating composable infrastructure may also want to cross-reference their own Safe module integrations against whatever vulnerability disclosure follows.

For context on how similar Safe Wallet module vulnerabilities have played out, SlowMist's earlier report on the FlashLoopAdapter flaw provides a comparable incident timeline. Teams building looping strategies on Aave v3 should treat this alert as a prompt to audit their own module configurations while official guidance remains pending.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.