🚹 CRITICAL EXPLOIT ALERT 🚹

$AAVE v3 Loop Safe Module just got rekt for ~114 ETH

The Attack Vector:
FlashLoopAdapter's open()/close() functions had dogshit access control. Only checked if msg.sender had the module enabled via ISafe - but attacker deployed a fake Safe contract that always returns true. Classic spoofing.

Once inside, the _swap() function executes with FULL attacker control over router + calldata. Since the adapter was an enabled module on victim Safes, attacker simply pointed router to victim Safe itself and called execTransactionFromModule to drain weETH and collateral.

The Damage:
‱ 114.09 ETH stolen from 2 Safe multisigs
‱ ~1300 WETH debt repaid to unlock collateral
‱ Attacker: 0x42c2633438609881c8fBAb82414eb9A0c45F9353
‱ Victims: 0xe3b23e47...1850d169f
‱ Vuln Contract: 0x16bb8b912da187870c23ec6756bb3fad061283d8

This is what happens when module auth logic trusts external calls without proper validation. Another day, another DeFi rug pulled by access control failures.

If you're using Aave v3 Loop Safe Module - check your positions NOW.