Aave v3 Loop Safe Module Attacked, Resulting in 114 ETH Loss
Written with artificial intelligence.

Aave's v3 Loop Safe module suffered an attack, with the assailant exploiting a vulnerability in the FlashLoopAdapter's open()/close() access control. Approximately 114.09 ETH was stolen from two Safe multi-signature addresses, while around 1300 WETH debts were repaid to unlock collateral.
Incident Overview
On October 2, PANews reported that the Aave v3 Loop Safe module was compromised due to a security flaw. The attacker took advantage of an access control vulnerability in the FlashLoopAdapter, allowing unauthorized actions through forged Safe certifications.
Details of the Attack
From the attack, approximately 114.09 ETH was stolen from two Safe multi-signature addresses. Additionally, the attacker repaid around 1300 WETH in debts to release the collateral linked to those addresses.
Ongoing Investigations
The incident is being tracked within the broader context of a significant theft involving Bitget, which reported around $387 million in stolen assets. Investigations are focusing on the timeline of events, attack vectors, and the flow of funds related to both incidents.