SlowMist Alert: Aave v3 Loop Safe Module Exploited for 114.09 ETH
Key Takeaways
- •SlowMist reported via a public security alert that the Aave v3 Loop Safe Module was exploited, with roughly 114.09 ETH stolen.
- •The exploit targeted an integration-layer module that supports looped leverage strategies, not the core contracts of the Aave v3 protocol itself.
- •Key details such as the attack vector, attacker wallet address, transaction hash, and a fiat equivalent of the loss were absent from the initial alert.
- •Aave v3 ranks among the largest DeFi lending protocols by total value locked on Ethereum, giving the module-level incident notable relevance.
- •The event mirrors a broader industry pattern of integration-layer exploits, comparable to the Zeus Wallet cyberattack, in which peripheral components rather than core logic were attacked.

Blockchain security firm SlowMist has issued an alert warning that the Aave v3 Loop Safe Module was exploited, with approximately 114.09 ETH reported stolen. The incident involves a specific module built on top of Aave v3, the decentralized lending protocol, and is distinct from a compromise of Aave v3's core contracts. The mechanism behind the attack was not immediately detailed in the alert.
SlowMist Reports Exploit of the Aave v3 Loop Safe Module
SlowMist, a firm specializing in blockchain security audits and threat monitoring, reported the exploit through a public security alert. The firm identified the Aave v3 Loop Safe Module — a component that enables looped leverage strategies within Aave v3 positions — as the target. The alert characterizes the event as an exploit of the named module rather than a protocol-wide breach of Aave v3 itself.
Looped leverage strategies generally involve repeatedly supplying an asset as collateral and borrowing against it to amplify exposure within a single position. A module facilitating this process operates at the integration layer, sitting between user positions and a protocol's core markets — a layer that has increasingly drawn the attention of attackers in incidents across the industry. Because such modules interact directly with user positions, an exploit at this layer can put the strategies built on the module at risk even when a protocol's core contracts remain intact.
The distinction carries weight. Aave v3 ranks among the largest decentralized finance (DeFi) lending protocols by total value locked on Ethereum. A module-level exploit does not automatically indicate that the protocol's underlying core contracts were compromised, though the full scope of the impact had not been confirmed at the time of SlowMist's alert. The incident follows a broader pattern of integration-layer exploits, similar to the Zeus Wallet cyberattack, in which a peripheral component was targeted rather than core logic.
Reported Loss Is Approximately 114.09 ETH
According to SlowMist's alert, approximately 114.09 ETH was stolen in the exploit. The alert confirmed no fiat equivalent for the amount, and no attacker wallet address or transaction hash was provided in the available information, preventing on-chain verification of the reported figure at this stage. Recent on-chain activity involving ETH wallet movements has drawn heightened attention to security across Ethereum-based protocols.
The precision of the 114.09 ETH figure is consistent with how automated on-chain exploit proceeds are often calculated, though the mechanism behind this specific incident has not been confirmed by SlowMist or Aave governance communications in the available sourcing. Alerts of this kind generally function as early warnings, published while details such as the attack vector and the number of affected positions are still being established.
What Is Confirmed and What Remains Unverified
The available evidence supports three facts:
- The alert source is SlowMist, a blockchain security firm.
- The target is the Aave v3 Loop Safe Module, not Aave v3's core contracts.
- The reported loss is approximately 114.09 ETH.
The exploit method, the number of affected users, whether funds have been frozen or recovered, and any remediation steps have not been confirmed in the information provided.
Users interacting with looped leverage positions on Aave v3 through third-party or integrated modules should monitor official Aave governance forums and SlowMist's public communications for further updates. Until a post-mortem or official confirmation is published, the root cause and the full scope of the impact remain unverified.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.