CRYPTOCURRENCY NEWS

SlowMist Alert: Aave v3 Loop Safe Module Exploited, 114.09 ETH Stolen

SlowMist, which has previously documented incidents including phishing campaigns costing platform users over $1 million and tampered cold wallet risks , published an alert identifying the Aave v3 Loop Safe Module as the target.

Share:

SlowMist Security Alert: Aave v3 Loop Safe Module Targeted

SlowMist, which has previously documented incidents including phishing campaigns costing platform users over $1 million and tampered cold wallet risks, published an alert identifying the Aave v3 Loop Safe Module as the target. The firm named the specific module rather than the core Aave v3 protocol itself, a distinction that matters for assessing the scope of exposure.

The Loop Safe Module is a peripheral component that extends Aave v3 functionality, not the core lending contracts. SlowMist’s alert framed the incident as an active exploit rather than a theoretical vulnerability disclosure.

Approximately 114.09 ETH Reported Stolen

SlowMist reported that approximately 114.09 ETH was taken in the exploit. The firm used the qualifier “approximately,” indicating the loss figure may be subject to revision as on-chain analysis continues. No fiat conversion was included in the alert, and independent blockchain confirmation of the specific transaction hash had not been publicly released at the time of this report.

The scale places this incident in the mid-tier range of DeFi exploits. For context, the Resupply protocol theft via interest rate manipulation and SlowMist’s Cork Protocol price manipulation warning illustrate the range of attack vectors currently active across lending and yield infrastructure.

What Remains Unconfirmed

SlowMist’s alert does not include attacker identity, the specific exploit mechanism, whether affected funds are recoverable, or any remediation steps from the Aave team. Users holding positions that interact with the Loop Safe Module should monitor the official Aave governance forum and SlowMist’s security channels for updated guidance.

This is not the first time SlowMist has flagged vulnerabilities connected to modular DeFi extensions. The firm’s analysis of the Cetus Protocol exploit impacting the SUI ecosystem similarly identified a peripheral module as the attack surface rather than a core protocol contract. The pattern suggests that security audits of composable add-ons deserve the same scrutiny applied to base-layer code.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Stay ahead of the market

Get daily crypto insights delivered to your inbox.

Related Articles

View all →