SlowMist issued a security alert saying a vulnerability in the Aave V3 Loop Safe Module was exploited to steal about 114.09 ETH from two Safe multisig wallets. According to the security firm, the attacker forged Safe authentication and then abused arbitrary Module execution to move funds. The exploit path involved a fake Safe that always returned a true value, which allowed the attacker to bypass verification checks. SlowMist said the attacker also used a router and calldata that could be controlled arbitrarily to execute module transactions, transferring weETH and Aave collateral out of the affected wallets. After that, the attacker repaid about 1,300 WETH in debt, which unlocked the collateral. The alert identifies the affected component as the Aave V3 Loop Safe Module and ties the loss to two Safe multisig wallets.
Odaily reported that blockchain security firm SlowMist had issued an alert over a vulnerability in the Aave V3 Loop Safe Module. The flaw was used to steal about 114.09 ETH from two Safe multisig wallets after the attacker forged Safe authentication and abused arbitrary Module execution.
According to SlowMist, the attacker bypassed authentication by forging a Safe that always returned a true value. The attacker then used a router and calldata that could be controlled arbitrarily to execute module transactions, moving weETH and Aave collateral. SlowMist said the attacker later repaid about 1,300 WETH in debt, which unlocked the collateral.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.