# Aave V3 Loop Module Exploit Drains About 114 ETH

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/26274
Published: 2026-10-02T03:07:14.000Z
Updated: 2026-10-02T03:07:14.000Z
Section: Technology

> The attack used access-control flaws in FlashLoopAdapter to take funds from two Safe multisignature addresses.

An exploit targeting Aave V3’s Loop Safe Module drained about 114.09 Ether (ETH) from two Safe multisignature addresses, using access-control flaws in the FlashLoopAdapter contract’s open() and close() functions.

The attacker used forged Safe authentication and unauthorized module execution to take the ETH. About 1,300 wrapped Ether (WETH) in debt was then repaid, allowing collateral to be unlocked.

The incident involved the Loop Safe Module and its adapter, which handle looping operations through Aave V3. The available details do not identify a recovery effort or a next step.
