Skip to content
$305K Stolen from Ethereum Safe Wallets via Aave V3 Exploit

$305K Stolen from Ethereum Safe Wallets via Aave V3 Exploit

First seen 2 Oct 2026, 10:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 10:08 UTC
  • •An exploit in Aave V3's Loop Safe Module led to the theft of $305,000.
  • •The attacker bypassed access controls using a fake Safe contract.
  • •AAVE's token price remains resilient despite the security breach.

An attacker exploited a vulnerability in the FlashLoopAdapter of Aave V3's Loop Safe Module, resulting in the theft of approximately $305,000 from two Ethereum Safe wallets. The attacker used a fake Safe contract to bypass access controls, repaid Aave debt with a Morpho flash loan, and withdrew collateral, retaining around 114.09 ETH. The exploit specifically targeted the open() and close() functions of the FlashLoopAdapter, allowing unauthorized access and execution. Despite the breach, Aave's core protocol remained unaffected, and no recovery actions have been reported. AAVE's token price has shown resilience, trading positively despite the incident. The incident underscores the risks associated with third-party modules in DeFi protocols, highlighting the need for improved access controls.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
Exploit discovered
An attacker exploited the FlashLoopAdapter in Aave V3, draining 114.09 ETH from two Safe wallets.
Pluang
2026-10-02
AAVE price increase
Despite the exploit, AAVE's price rose by 8.38% within 24 hours, indicating market resilience.
Pluang

More articles in this cluster (2)

Following this threat?

Track DeFi Saver in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What was stolen in the exploit?
Approximately $305,000 worth of Ether (ETH) was stolen from two Ethereum Safe wallets.
Is Aave's core protocol affected?
No, the core Aave protocol remains unaffected by this exploit.
What should users of Aave do?
Users should monitor their wallets and consider enhancing security measures, particularly regarding third-party modules.