SlowMist issued a security alert on October 2 flagging an access-control vulnerability in FlashLoopAdapter's open() and close() functions inside Aave v3's Loop Safe Module. Two Safe multisigs that opted into the module lost roughly 114.09 ETH, about $305,000.
Why it matters
The bug let the attacker call open() and close() on positions that did not belong to them, draining the underlying collateral. SlowMist traced the attacker's transactions and classified it as an access-control failure, not a flash-loan or oracle exploit.
The dollar figure is small by Aave standards, but the location matters. The Loop Safe Module exists to let Safe wallet owners automate leveraged Aave v3 positions without signing every transaction. Modules run with broad permissions on a Safe, so any access-control bug in a popular module compounds trust assumptions across thousands of user-configured wallets.
Market impact
Aave's core lending markets and the AAVE token itself were not directly affected. The remaining open questions are whether the FlashLoopAdapter contract was deployed by the Aave team or a third party, and how many Safe wallets had approved it before any patch.
Frequently asked questions
-
What is the FlashLoopAdapter vulnerability on Aave v3?
An access-control bug in FlashLoopAdapter's open() and close() functions let an attacker call those functions on positions that did not belong to them, draining the underlying collateral from Safe wallets that had opted into Aave v3's Loop Safe Module.
-
How much was stolen in the Aave v3 FlashLoopAdapter exploit?
Roughly 114.09 ETH, worth about $305,000 at the time of the October 2 incident. Only two Safe multisigs were affected, and Aave's core lending markets remain functional.
-
Is the Aave v3 protocol itself at risk from this exploit?
The bug is isolated to the FlashLoopAdapter contract inside the Loop Safe Module, not Aave v3's core lending pools. AAVE and the broader protocol were not directly affected.
-
What is Aave v3's Loop Safe Module?
It is a module that lets Safe wallet owners automate leveraged Aave v3 positions without signing every transaction. Modules run with broad permissions on a Safe, which is why an access-control bug in any module carries outsized risk.
-
Who flagged the FlashLoopAdapter exploit?
SlowMist issued a security alert on October 2, 2026, tracing the attacker's on-chain transactions. Wu Blockchain reported the alert publicly the same day.
Crypto News