NewsCryptoSlowMist Alert: Aave v3 Loop Safe Module Exploited, Approximately 114.09 ETH Stolen

SlowMist Alert: Aave v3 Loop Safe Module Exploited, Approximately 114.09 ETH Stolen

Author: AI Crypto Core·

Key Takeaways

  • •SlowMist reported that the Aave v3 Loop Safe Module was exploited, with approximately 114.09 ETH stolen in the incident.
  • •The module is an auxiliary layer for looped leverage positions built on top of Aave v3's core lending infrastructure, and its compromise is distinct from a breach of Aave's base protocol contracts.
  • •The exploit method and the identity of the attacker remain unconfirmed, and no USD valuation of the loss was provided.
  • •Aave v3's core lending pools were not confirmed as affected, and users of loop products are advised to verify their exposure through official Aave governance or security communications.
  • •The incident reflects a recurring DeFi pattern in which peripheral or wrapper components, rather than audited core protocols, become the attack surface, as previously seen in the GMX and BigONE exploits.
SlowMist Alert: Aave v3 Loop Safe Module Exploited, Approximately 114.09 ETH Stolen

Blockchain security firm SlowMist has issued an alert reporting that the Aave v3 Loop Safe Module was exploited, with approximately 114.09 ETH stolen in the incident. The alert names the affected component directly and flags the theft as an active security event for Aave protocol users and decentralized finance (DeFi) participants monitoring on-chain risk.

What SlowMist's Alert Says

SlowMist, which operates as an on-chain threat intelligence and smart contract auditing firm, identified the Aave v3 Loop Safe Module as the exploited component. The module functions as an auxiliary layer built on top of Aave v3's core lending infrastructure, designed to facilitate looped leverage positions within a defined safety boundary. In DeFi, looping generally refers to repeatedly supplying an asset as collateral, borrowing against it, and redepositing the borrowed amount to scale a single position — a strategy that magnifies both returns and liquidation risk. Its compromise is distinct from a breach of Aave's core protocol contracts.

The alert does not confirm the exploit method or identify the attacker, and those details remain unverified at the time of publication. Users interacting with loop-based strategies on Aave v3 should treat any unconfirmed remediation steps circulating on social channels with caution until an official post-mortem is released by the relevant development team. Developments to watch as the incident unfolds include a confirmed exploit vector, any on-chain movement of the stolen funds, and the release of the official post-mortem.

A Familiar Pattern in DeFi Module Exploits

Incidents of this type share a structural pattern with the suspected ResolvLabs USR exploit flagged by on-chain analysts, in which auxiliary or wrapper contracts built atop base protocols become the attack surface rather than the underlying protocol itself.

Approximately 114.09 ETH Stolen: What It Means for Users

The reported loss stands at approximately 114.09 ETH. No USD equivalent was confirmed in SlowMist's alert, and current Ethereum market data was unavailable at publication time, so a dollar conversion is omitted here to avoid unsupported figures.

Aave v3's core lending pools were not confirmed as affected. The distinction matters for users holding collateral or debt positions directly within the main Aave v3 markets, as opposed to those using loop or leverage modules layered on top. Users with active positions in any Aave v3 loop product should verify their exposure against official Aave governance or security communications.

Peripheral Components as the Weak Point

Incidents such as the $42 million GMX exploit on Arbitrum and the $27 million BigONE exchange hack illustrate that smart contract security failures frequently originate outside core protocol logic — in modules, wrappers, or off-chain integrations that interact with audited base contracts. The BigONE hot wallet exploit similarly demonstrated how peripheral components carry independent attack surfaces that may not receive audit scrutiny equivalent to that applied to base protocols.

Composability Risk and Automated Strategies

From a decentralized protocol security standpoint, the incident highlights a recurring gap in composability risk assessment: auxiliary modules often inherit implied trust from the audited protocol they wrap. On-chain AI agent infrastructure and automated DeFi strategies that programmatically interact with loop modules face compounded exposure when those modules are compromised mid-execution, since automated position management cannot self-interrupt without explicit circuit-breaker logic.


Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.