AAVE JUST LOST 114 $ETH TO A SAFE MODULE EXPLOIT.

A vulnerability in Aave V3’s Loop Safety Module reportedly allowed an attacker to bypass Safe authentication and drain around 114.09 ETH from two Safe multisig wallets.

The attack reportedly involved:

Spoofing the Safe identity to pass authentication

Using an arbitrary module to execute transactions

Controlling the router and calldata

Moving weETH and Aave collateral

Repaying around 1,300 WETH in debt

Unlocking and withdrawing the underlying collateral

Safe: “Is this really a Safe wallet?”
Attacker: “Yes.”
Safe: “Looks legit.”

114 ETH disappeared because the security check basically said: “Trust me bro.”