What was hit were not the lending markets of Aave but two individual wallets that had an add-on module switched on. According to the security firm SlowMist, around 114.09 ETH flowed out of two Safe multisig wallets because the access control of an external helper contract around Aave v3 could be bypassed. Anyone running a Safe of their own therefore has a clearly defined task: look at which modules are active there, and switch off everything that is not needed.
A Safe multisig is a wallet that sits on the blockchain as a contract and only acts once a set number of signatures has come together. A module is an additional contract that this wallet allows to trigger transactions even without the full signing quorum. It was precisely that short cut which was used here.
The attack in detail: FlashLoopAdapter, a forged Safe and 114.09 ETH
The component attacked is called FlashLoopAdapter and sits at the address 0x16bb8b912da187870c23ec6756bb3fad061283d8. According to SlowMist's analysis, which the firm published on October 2, 2026 via its X channel and which


English (US)