SlowMist Issues Alert on the Aave v3 Loop Safe Module
SlowMist, a widely followed on-chain security monitoring firm, issued the alert flagging the Aave v3 Loop Safe Module as compromised. The report identifies the module by name, distinguishing this incident from a broader Aave v3 protocol vulnerability. For related coverage, see Aave Monad Market Surpasses $100M in Deposits Two Days After Launch.
This is not the first time a looping adapter attached to Aave has drawn scrutiny. An earlier incident saw a FlashLoopAdapter flaw drain two Safe wallets of their collateral, a structurally similar pattern involving third-party modules layered on top of Aave’s core contracts. The Aave founder also previously confirmed a $310K exploit hitting a third-party adapter, reinforcing that the risk surface often lies at the integration layer rather than inside Aave’s audited core.
Approximately 114.09 ETH Reported Stolen
According to the SlowMist alert, approximately 114.09 ETH was stolen in the exploit. The figure is attributed solely to SlowMist’s report and has not been confirmed by an independent on-chain source at the time of writing. Readers should treat it as a reported estimate until corroborated by a block explorer trace or official statement.
The loss amount is notable in context: Aave controls 47.8% of active onchain loans, making its module ecosystem a high-value target. Any exploit touching Aave-adjacent infrastructure draws immediate attention from both users and security researchers tracking the protocol’s total value locked.
What This Means for Aave Users
Users who interact with loop or leverage strategies built on top of Aave v3, particularly those routed through Safe (formerly Gnosis Safe) wallet infrastructure, should review their current exposure. If you have active positions using a looping module, check whether the specific module you are using matches the one named in the SlowMist alert before taking any action.
Do not rely solely on this report. Monitor the official Aave governance channels and SlowMist’s verified social accounts for updated findings and any remediation steps. The Aave protocol itself has not issued a statement at time of publication, and no patch or mitigation has been publicly announced.
Is this another reminder that third-party adapters remain the weakest link in DeFi’s security chain, or does it point to something deeper in how looping strategies interact with Safe module permissions?
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.