入门 Aave v3 Loop Safe Module Exploited: $114.09 ETH Stolen, Confirmed by SlowMist
On 2026-10-02, blockchain security firm SlowMist confirmed an exploit against the Aave v3 Loop Safe Module — a third-party integration designed to automate looping strategies on Aave’s V3 protocol. Approximately 114.09 ETH was extracted from affected user positions. The attack did not target Aave’s core contracts but exploited logic flaws in how the Loop Safe Module handled permissioned calls and reentrancy safeguards. No user funds held directly in Aave v3 were compromised. The figure reflects on-chain transaction data verified by SlowMist’s post-incident analysis.
SlowMist’s report identifies a vulnerability in the module’s executeOperation implementation, where insufficient validation allowed an attacker to manipulate call order during flash loan–driven loops. The module permitted arbitrary contract calls without enforcing strict caller whitelisting or state checks between successive operations. This enabled recursive execution paths that bypassed expected safety gates. The exploit was executed in a single transaction on Ethereum mainnet, confirmed via on-chain trace analysis. SlowMist did not publish the exact block height or timestamp of the transaction, only the date of its public disclosure: 2026-10-02.
Users who had previously authorized the Loop Safe Module to manage their Aave v3 positions — particularly those using leveraged yield strategies involving USDC, DAI, or WETH — faced unintended liquidations or fund diversion. The stolen ETH came from users’ collateralized borrowing positions, not Aave’s treasury or protocol reserves. This highlights a structural shift: risk is no longer confined to protocol-native code. Third-party modules like Loop Safe now represent distinct attack surfaces with independent governance, audit history, and upgrade mechanisms. For market participants tracking asset correlations, this event introduces new basis risk — e.g., ETH price volatility may now compound with module-specific smart contract risk, especially for tokens used as loop anchors. Regulatory scrutiny may follow, as such modules blur lines between DeFi infrastructure and unregistered financial intermediation.
SlowMist’s report does not specify whether the module has been paused, upgraded, or deprecated. It also does not disclose whether any funds have been recovered or whether the attacker’s address has been tagged by major blockchain intelligence firms. Crucially, the report omits the USD value of the stolen ETH at time of theft — meaning readers cannot assess relative severity against prior DeFi incidents (e.g., the $118M Euler Finance exploit in 2023). Without on-chain evidence of mitigation steps or wallet-level forensic details, downstream effects — including potential contagion to other Safe-based automation tools — remain speculative. This uncertainty affects both liquidity providers assessing counterparty risk and institutional custodians evaluating custody policy for multi-signature vaults linked to such modules.
This article reports factual findings from SlowMist’s public disclosure dated 2026-10-02. It does not constitute financial, legal, or tax advice. Cryptocurrency investments carry high volatility and irreversible loss risk. The figures cited (114.09 ETH) originate solely from wublock123.com and reflect on-chain observations, not real-time valuations. cryptodlhub receives compensation for referrals to third-party services; this includes commissions from the /go/binance-download/ page. We do not endorse Binance’s products, nor do we guarantee performance, security, or regulatory compliance of any platform referenced. Readers should independently verify all claims before acting. For foundational concepts, see our Glossary and News sections.
Risk warning and disclosure
Investing involves risk and market risk; official live rules always apply. Some outbound links may be affiliate links and we may earn a commission. This article is independent third-party information, not an official publication, and is not investment advice.
Related reading
Related News
入门 SEC approves 3x leveraged Bitcoin and Ethereum ETPs
The U.S. Securities and Exchange Commission approved three 3x daily leveraged exchange-traded products tied to Bitcoin and Ethereum on October 3, 2026 — t…
入门 NEAR Intents exploiter sends 1 BNB to recovery wallet, signals cooperation
An unidentified actor who exploited the NEAR Intents vulnerability transferred 1 BNB to a recovery wallet on October 3, 2026, and indicated willingness to…
入门 IMF approves $139M disbursement to El Salvador and waives Bitcoin reserve cap
The IMF approved a $139 million disbursement under El Salvador’s Extended Fund Facility and waived its 15% Bitcoin reserve limit through June 2027 — condi…
Follow the market on a major exchange
Download Binance or OKX from the official website to start trading.