
Aave v3 exploit drains $310K by abusing a third-party Safe module on Ethereum multisigs
On October 1, 2026, an attacker exploited a vulnerability in a third-party FlashLoopAdapter module linked to Aave v3 to drain about $305K-$310K from two Safe multisig wallets on Ethereum. The attacker forged Safe authentication to bypass access contr...





