SlowMist2026-10-02 03:06:46SlowMist flags Aave V3 Loop Safe Module flaw after about 114.09 ETH stolenSlowMist issued a security alert saying the Aave V3 Loop Safe Module contained a vulnerability that was exploited to steal about 114.09 ETH from two Safe multisig wallets. According to the alert, the attacker forged Safe authentication by using a fake Safe that always returned a true value, which let the exploit bypass the module’s verification checks. The attacker then abused arbitrary module execution through a controllable router and calldata to carry out module transactions. During the attack, weETH and Aave collateral were moved out of the affected wallets. SlowMist also said the attacker repaid about 1,300 WETH in debt, which unlocked the collateral before the assets were transferred. The alert focuses on the exploit path and the mechanics of the theft, without providing additional details on recovery or mitigation in the cited notice.70
SlowMist2026-10-02 03:06:33SlowMist says Aave V3 Loop Safe Module flaw led to theft of about 114.09 ETH from two Safe multisig walletsSlowMist issued a security alert saying a vulnerability in the Aave V3 Loop Safe Module was exploited to steal about 114.09 ETH from two Safe multisig wallets. According to the security firm, the attacker forged Safe authentication and then abused arbitrary Module execution to move funds. The exploit path involved a fake Safe that always returned a true value, which allowed the attacker to bypass verification checks. SlowMist said the attacker also used a router and calldata that could be controlled arbitrarily to execute module transactions, transferring weETH and Aave collateral out of the affected wallets. After that, the attacker repaid about 1,300 WETH in debt, which unlocked the collateral. The alert identifies the affected component as the Aave V3 Loop Safe Module and ties the loss to two Safe multisig wallets.60
CoinDesk2026-09-15 10:27:55Security firms say $7.8 million wallet drain came from authorized helper contract, not SafeSecurity firms traced a $7.8 million crypto wallet loss to an authorized helper contract rather than to Safe itself, according to CoinDesk. The available details point to a simple coding mistake as the opening that allowed the attacker to drain the funds. That distinction matters because the incident was not attributed to a flaw in Safe, but to a contract the wallet owner had previously approved. CoinDesk’s summary did not provide additional technical details, a timeline of the exploit beyond the report date, or the identity of the wallet owner and attacker.250
TGE2026-09-15 01:38:23Begin Capital partner says weak TGE debuts expose three structural flaws in crypto token financingA Begin Capital partner has argued that the crypto industry’s so-called "tokenized IPO" model has turned into a market structure where projects can reach token issuance without proving profitability or real user demand, while retail traders end up providing exit liquidity. In comments cited by BlockTempo, the investor said most token generation event, or TGE, launches now fall below issue price shortly after listing, while the few that rise against the trend often trigger compliance questions. The piece centers on SAFT, or Simple Agreement for Future Tokens, a fundraising structure that gives investors rights to receive tokens after a mainnet launch or TGE. The author describes that setup as something closer to a mix of a prediction market and gambling than a conventional financing path. In that view, the system has long operated with three missing pieces: meaningful review, fundamental business anchoring, and transparency. The article also says the market is shifting. SAFE and SAFT are now often used together, due diligence is moving closer to Web2 standards, and capital is increasingly flowing toward sectors that have already shown product-market fit, revenue, and understandable business models. Areas named in the piece include betting and prediction markets, meme coin launch platforms, payments, digital neobanks, fiat on- and off-ramps, and AI, while DePIN and RWA were described as drawing comparatively less funding.440
Policy and Re2026-09-15 00:46:00Venture Partner Says Crypto’s Token Launch Casino Model Is Breaking DownPaul Klay, a venture partner at Begin Capital, argues that the weak post-TGE performance seen across most token launches points to a deeper breakdown in crypto’s old fundraising model. In his view, the structure built around SAFT-based investing gave projects a way to generate liquidity even when the underlying business had not succeeded, creating a market dynamic closer to gambling than a traditional path to value creation. He says the model has three core flaws: token valuations often have little connection to business fundamentals, key parts of the launch process remain opaque to outside investors, and the number of moving parts in a launch makes outcomes highly sensitive to execution. Klay adds that the market is now shifting toward deals that combine SAFE and SAFT structures, heavier due diligence, and stronger attention to revenue, understandable business models, and product-market fit. He also says capital is flowing more readily to areas such as prediction markets, meme coin launchpads, payments, digital neo-banks, fiat on- and off-ramps, and AI, while DePIN and RWA are attracting relatively less funding.1160
ChainCatcher2026-09-09 13:23:13Two newly created wallets claimed and sold LAPTOP for more than $647,000 in combined profitChainCatcher reported, citing on-chain analyst @ai_9684xtpa, that two newly created wallets claimed 4,276 LAPTOP each from the Hunter Biden Substack subscriber airdrop contract around 40 minutes earlier and then sold the tokens. The two wallets received about $404,000 and $243,000 respectively from the sales, bringing combined profit to more than $647,000. On-chain data also showed an ETH transfer link between the two addresses. One of them, 0x8DA…4A18d, later transferred the USDC proceeds from the sale to a publicly labeled address belonging to Safe architect FloB (@FloB_Safe). The report did not provide further detail beyond the observed token claims, sales, and address connections.720
Safe2026-09-09 08:50:18Safe to launch Safe Pro on Oct. 6 and open early partner applicationsMultisig wallet provider Safe said it will launch Safe Pro on Oct. 6, introducing a product aimed at organizations rather than individual users. According to the announcement cited by ChainCatcher, Safe Pro will offer enterprise-grade management tools, extra security features, audit history, and reporting for all Safe accounts operated by a given organization. The package will also include guided onboarding and professional support, while keeping self-custody unchanged. Ahead of the release, Safe has opened an early partner program for teams that want to work directly with the company and help shape the product before launch. The application link is available through Safe’s official post.850
Shibarium2026-09-04 12:01:55Shibarium Completes Deployment of Safe v1.4.1 Multisig Wallet ContractsSHIB community member Mazrael announced that Shibarium has deployed and verified all nine contracts of Safe v1.4.1, with PR#1666 submitted for registration. The deployment uses standard factory addresses, aligning Shibarium multisig addresses with other networks, a feature previously unavailable on v1.3.0.790