LIVE
SingularityNET Issues Update on Security Incident◆USDT Address-Poisoning Attack Costs $67,572◆AMLBot Traces 4 BTC From Bitget Hack to Wasabi◆Coinbase Launches Fixed-Rate USDC Loans Backed by cbBTC◆GoBTC Pay Tests Bitcoin Payments for Agentic Commerce at Agnic.AI Hackathon◆DOJ Probes Binance Over Possible Iran Sanctions Breach◆$999M Floods Into Bitcoin ETFs as BTC Price Explodes Higher◆SingularityNET Reports Unauthorized System Access◆Bitcoin Hits $86K as Dogecoin Leads Crypto Rally◆Circle Launches Bitcoin-Backed USDC Loans for Institutions◆SingularityNET Issues Update on Security Incident◆USDT Address-Poisoning Attack Costs $67,572◆AMLBot Traces 4 BTC From Bitget Hack to Wasabi◆Coinbase Launches Fixed-Rate USDC Loans Backed by cbBTC◆GoBTC Pay Tests Bitcoin Payments for Agentic Commerce at Agnic.AI Hackathon◆DOJ Probes Binance Over Possible Iran Sanctions Breach◆$999M Floods Into Bitcoin ETFs as BTC Price Explodes Higher◆SingularityNET Reports Unauthorized System Access◆Bitcoin Hits $86K as Dogecoin Leads Crypto Rally◆Circle Launches Bitcoin-Backed USDC Loans for Institutions◆
Homepage/News/Aave v3 Loop Safe Module Exploited; 114.09 ETH Stolen
NEWS

Aave v3 Loop Safe Module Exploited; 114.09 ETH Stolen

·2 MIN READ·
MakeThe CC Presspreferred onGoogle

A security alert from blockchain security firm SlowMist reports that the Aave v3 Loop Safe Module has been exploited, with approximately 114.09 ETH stolen from affected users. The alert names a specific module within the Aave v3 ecosystem as the attack vector, though full technical details of the exploit have not been independently verified at the time of publication.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
3Key sections mapped in this report
0Internal references connected to related coverage
3External source domains cited in the article
2 minEstimated time to read the full report

SlowMist Issues Alert on the Aave v3 Loop Safe Module

SlowMist, a widely followed on-chain security monitoring firm, issued the alert flagging the Aave v3 Loop Safe Module as compromised. The report identifies the module by name, distinguishing this incident from a broader Aave v3 protocol vulnerability. For related coverage, see Aave Monad Market Surpasses $100M in Deposits Two Days After Launch.

This is not the first time a looping adapter attached to Aave has drawn scrutiny. An earlier incident saw a FlashLoopAdapter flaw drain two Safe wallets of their collateral, a structurally similar pattern involving third-party modules layered on top of Aave’s core contracts. The Aave founder also previously confirmed a $310K exploit hitting a third-party adapter, reinforcing that the risk surface often lies at the integration layer rather than inside Aave’s audited core.

Approximately 114.09 ETH Reported Stolen

According to the SlowMist alert, approximately 114.09 ETH was stolen in the exploit. The figure is attributed solely to SlowMist’s report and has not been confirmed by an independent on-chain source at the time of writing. Readers should treat it as a reported estimate until corroborated by a block explorer trace or official statement.

The loss amount is notable in context: Aave controls 47.8% of active onchain loans, making its module ecosystem a high-value target. Any exploit touching Aave-adjacent infrastructure draws immediate attention from both users and security researchers tracking the protocol’s total value locked.

What This Means for Aave Users

Users who interact with loop or leverage strategies built on top of Aave v3, particularly those routed through Safe (formerly Gnosis Safe) wallet infrastructure, should review their current exposure. If you have active positions using a looping module, check whether the specific module you are using matches the one named in the SlowMist alert before taking any action.

Do not rely solely on this report. Monitor the official Aave governance channels and SlowMist’s verified social accounts for updated findings and any remediation steps. The Aave protocol itself has not issued a statement at time of publication, and no patch or mitigation has been publicly announced.

Is this another reminder that third-party adapters remain the weakest link in DeFi’s security chain, or does it point to something deeper in how looping strategies interact with Safe module permissions?

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: slowmist.com
  • External Source - Referenced domain: theccpress.com
  • External Source - Referenced domain: defillama.com
  • Byline - Reported by Joshua Trelawen
  • Coverage Desk - Primary editorial category: News
  • Media Asset - Featured image served from the WordPress media library