Security Flaw in Aave Module Allows Attacker to Drain $305,000 From Multisignature Wallets

A vulnerability in Aave V3's Loop Safe Module enabled attackers to bypass wallet authorization and steal approximately $305,000 from two multisignature wallets. The exploit involved two distinct weaknesses: an access-control flaw in the FlashLoopAdapter that allowed attackers to create counterfeit Safe contracts that bypassed verification checks, and insufficient controls over swap instructions that gave attackers excessive authority over transaction routing. Security firm SlowMist issued a public alert detailing how the vulnerability worked and its potential impact on affected users.
The FlashLoopAdapter module was designed to help Safe wallet users manage leveraged positions on Aave V3 by automating complex transactions. The attacker's approach demonstrated how verification mechanisms can fail when they rely on self-reporting. By creating a counterfeit Safe contract that always confirmed trust in the module, the attacker bypassed the authentication layer that should have prevented unauthorized access.
The actual theft occurred through a single coordinated transaction funded by a flash loan. The attacker repaid outstanding AAVE debt positions held by the victims' wallets, which triggered the release of locked collateral. Because the compromised module had legitimate permission to interact with these wallets, it could instruct them to withdraw and transfer the newly available funds without triggering multisig approval.
This incident highlights risks inherent to modular wallet architectures, where security depends partly on third-party code. Aave users who employ similar automation modules may reassess their setup choices, potentially reducing protocol adoption among risk-averse participants. The incident could influence how developers design wallet integrations and security auditing practices across decentralized finance platforms, affecting both user protection standards and development timelines for new features.