In Transient
SlowMist studies an Aave v3 Loop Protected module exploit that drained 114 ETH through a spoofable entry management flaw; the core Aave protocol stays unaffected.

Blockchain safety agency SlowMist has issued an alert after the Aave v3 Loop Protected module was exploited via an access-control vulnerability, ensuing within the lack of roughly 114.09 ETH (round $305,000) from two Protected multisignature wallets. The assault, detected on October 1 by Defimon Alerts, focused the FlashLoopAdapter contract however left the core Aave v3 protocol untouched.
FlashLoopAdapter is a Protected module designed to automate the opening and shutting of leveraged positions on Aave v3. Based on SlowMist, the foundation reason for the exploit lay within the entry controls of the adapter’s `open()` and `shut()` capabilities. Reasonably than independently verifying the caller’s id, the capabilities merely checked that `ISafe(msg.sender).isModuleEnabled(handle(this))` returned true. An attacker may due to this fact deploy a faux Protected contract programmed to at all times return true, permitting the malicious caller to move the verification verify.
The attacker then exploited the module’s `_swap()` operate, which executes a uncooked name to a caller-supplied router with totally attacker-controlled calldata. By setting the router to a sufferer Protected handle and the calldata to `execTransactionFromModule` — a Protected operate that lets an enabled module execute transactions — the attacker successfully turned the adapter’s personal permissions right into a distant management over the victims’ wallets. As a result of FlashLoopAdapter was already enabled as a module on each focused Safes, the ensuing calls have been accepted with out situation.
The assault chain concerned greater than merely draining obtainable balances. The attacker took a Morpho WETH flash mortgage and used the borrowed funds to repay roughly 1,335 WETH of Aave debt belonging to the bigger pockets, recognized as 0xcfedf95a3653a128dfc2e4288758a1a1850d169f.
Repaying the debt unlocked the leveraged place’s collateral, after which the attacker had the Protected withdraw roughly 1,306 weETH to an attacker-controlled handle. A second Protected, 0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520, misplaced a further 6.4 weETH via the identical mechanism. Defimon Alerts famous that each wallets shared the identical single proprietor. After settling the flash mortgage and changing a part of the withdrawn collateral to WETH, the attacker retained round 114.1 ETH. The attacker handle was recognized as 0x42c2633438609881c8fBAb82414eb9A0c45F9353, whereas the susceptible contract sits at 0x16bb8b912da187870c23ec6756bb3fad061283d8.
Aave v3 core unaffected, echoing earlier Protected module incidents
In response to the incident, Aave founder and CEO Stani Kulechov clarified in a publish that the exploited code was not a part of Aave v3 itself however a third-party exterior adapter constructed on high of the protocol, with zero impact on the core contracts. Neither safety alert recognized any vulnerability in Aave v3, which continued to function usually.
The exploit nonetheless highlights a recurring sample within the Protected ecosystem. As a result of modules are granted the power to execute transactions from a pockets with out going via the usual proprietor approval move, a single flaw in a module’s authentication logic can expose all belongings underneath its management. The same weak point surfaced in September, when an Ethereum Protected exploit involving roughly 2,900 rsETH was traced to insufficient authorization checks in an executor contract tied to an enabled module. In Might, attackers drained roughly $3 million from 86 wallets by abusing the SquidRouterModule, and Gnosis Pay customers have been individually urged to withdraw funds after a flaw was present in its Zodiac delay module.
Disclaimer
In step with the Trust Project guidelines, please observe that the data offered on this web page will not be supposed to be and shouldn’t be interpreted as authorized, tax, funding, monetary, or another type of recommendation. You will need to solely make investments what you possibly can afford to lose and to hunt unbiased monetary recommendation you probably have any doubts. For additional info, we advise referring to the phrases and circumstances in addition to the assistance and help pages offered by the issuer or advertiser. MetaversePost is dedicated to correct, unbiased reporting, however market circumstances are topic to vary with out discover.
About The Creator
Alisa, a devoted journalist on the MPost, focuses on crypto, AI, investments, and the expansive realm of Web3. With a eager eye for rising traits and applied sciences, she delivers complete protection to tell and have interaction readers within the ever-evolving panorama of digital finance.
Alisa, a devoted journalist on the MPost, focuses on crypto, AI, investments, and the expansive realm of Web3. With a eager eye for rising traits and applied sciences, she delivers complete protection to tell and have interaction readers within the ever-evolving panorama of digital finance.






