Skip to content
Ethereum

Aave v3 Loop Safe Module Exploit Steals 114.09 ETH

White and violet crystalline Ethereum emblem floating above a neon circular platform.

The Aave ecosystem is facing renewed security scrutiny after SlowMist issued an alert about an exploit targeting the Aave v3 Loop Safe Module. According to a report reviewed by Wu Blockchain, the attacker stole approximately 114.09 ETH, worth roughly $280,000 at current market rates. The disclosure underscores how modular DeFi infrastructure can introduce new attack surfaces even when core lending markets remain intact.

What the SlowMist alert says

SlowMist’s warning points to the Loop Safe Module as the compromised component, not Aave’s core protocol. The module appears designed to support leveraged or looped positions through Safe accounts, combining smart account execution with Aave v3 lending logic. Early assessments suggest the exploit involved an access-control flaw or misconfigured permissions rather than a direct failure in Aave’s lending pools. Security teams are still reconstructing the full path, but the reported loss of 114.09 ETH places the incident in the mid-sized exploit range. The small but targeted nature of the exploit suggests a deliberate actor rather than an automated scanner. It also arrives amid broader Ethereum security concerns, including incidents such as Bitget Confirms $351.6M Security Incident; Cold Storage Remains Secure.

Implications for DeFi and what to watch

The exploit does not appear to indicate a compromise of Aave v3’s main liquidity pools, but it may complicate the narrative around modular vaults, smart accounts, and permissionless yield automation. Developers and integrators may review access-control defaults more aggressively before enabling similarly composed modules. The Aave community and SlowMist are likely to publish technical post-mortems, which could influence governance decisions on module whitelisting or front-end usage. Aave governance may also discuss whether module-level incident reporting should become more standardized. This event also fits into a broader conversation about how Ethereum’s programmability expands use cases while increasing the attack surface, a theme explored in Ethereum’s World Computer Shift and El Salvador Blockchain.

Security lessons for modular DeFi

For users, the incident reinforces that security assumptions should be applied to the entire execution stack, not just the underlying lending protocol. Smart accounts and automation modules can hold spending authority or token approval rights, making them sensitive targets even when the core protocol remains sound. Tooling that supports verifiable module permissions and time-delayed execution may gain traction as a response. Meanwhile, privacy-oriented infrastructure continues to expand on Ethereum, as seen in the launch of Ethereum Foundation Launches zkAPI for Private API Payments, which shows how technical innovation is running ahead of standard risk frameworks. Security researchers will likely monitor whether similar Safe modules are reused across other protocols.

BTC-Pulse

Related stories

More coverage from this topic.