SlowMist issued a security alert saying the Aave V3 Loop Safe Module contained a vulnerability that was exploited to steal about 114.09 ETH from two Safe multisig wallets. According to the alert, the attacker forged Safe authentication by using a fake Safe that always returned a true value, which let the exploit bypass the module’s verification checks. The attacker then abused arbitrary module execution through a controllable router and calldata to carry out module transactions. During the attack, weETH and Aave collateral were moved out of the affected wallets. SlowMist also said the attacker repaid about 1,300 WETH in debt, which unlocked the collateral before the assets were transferred. The alert focuses on the exploit path and the mechanics of the theft, without providing additional details on recovery or mitigation in the cited notice.
SlowMist has issued a security alert saying a vulnerability in the Aave V3 Loop Safe Module was exploited to steal about 114.09 ETH from two Safe multisig wallets, according to ChainCatcher.
How the exploit worked
SlowMist said the attacker bypassed authentication by forging a Safe that always returned a true value during verification. That allowed the attacker to get past the module’s checks and use arbitrary module execution.
The alert said the attacker then used a controllable router and calldata to execute module transactions, moving out weETH and Aave collateral.
Collateral unlocked after debt repayment
SlowMist added that the attacker repaid about 1,300 WETH in debt, which unlocked the collateral before the assets were transferred.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.