SlowMist TI Alert @aave v3 Loop Safe Module Loss: ~114.09 ETH Root Cause: FlashLoopAdapter's open()/close() access control only checks ISafe(msg.sender).isModuleEnabled(address(this)), which is spoofable via a fake Safe that always returns true. Its _swap() then executes http://router.call with fully attacker-controlled router and calldata. Since the adapter is an enabled module of the victim Safes, the attacker set router=victim Safe and data=execTransactionFromModule to drain weETH and Aave collateral. Attacker: 0x42c2633438609881c8fBAb82414eb9A0c45F9353 Victim: 0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520, 0xcfedf95a3653a128dfc2e4288758a1a1850d169f Vulnerable Contract: 0x16bb8b912da187870c23ec6756bb3fad061283d8 Impact: ~114.09 ETH stolen from two Safe multisigs via forged Safe authentication and arbitrary module execution; ~1300 WETH debt repaid to unlock collateral. Powered by http://SlowMist.AI Tx: https://(etherscan.io)/tx/0x75328f916b1a0878724d364da5eb12b255160b894cb36c63ed5d718efc616fc4
--
Loading...