SlowMist: Approximately 114.09 ETH Stolen, Aave v3 Loop Safe Module Vulnerability Affects Two Safe Multisig Wallets
Odaily reports that SlowMist has issued a security alert stating that a vulnerability has been discovered in the Aave V3 Loop Safe Module. Attackers exploited forged Safe authentication and arbitrary Module execution to steal approximately 114.09 ETH from two Safe multisig wallets.
The attackers bypassed authentication by forging a Safe that always returns true, and leveraged an arbitrarily controllable router and calldata to execute module transactions, transferring weETH and Aave collateral. The attackers repaid approximately 1,300 WETH in debt to unlock the collateral.
