BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Aave loop module: 114.09 ETH drained from two Safe multisigs, and what you can do now

What was hit were not the lending markets of Aave but two individual wallets that had an add-on module switched on. According to the security firm SlowMist, around 114.09 ETH flowed out of tw

AnonymousCryptoCompass newsroom
October 2, 2026
11 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

What was hit were not the lending markets of Aave but two individual wallets that had an add-on module switched on. According to the security firm SlowMist, around 114.09 ETH flowed out of two Safe multisig wallets because the access control of an external helper contract around Aave v3 could be bypassed. Anyone running a Safe of their own therefore has a clearly defined task: look at which modules are active there, and switch off everything that is not needed.

A Safe multisig is a wallet that sits on the blockchain as a contract and only acts once a set number of signatures has come together. A module is an additional contract that this wallet allows to trigger transactions even without the full signing quorum. It was precisely that short cut which was used here.

The attack in detail: FlashLoopAdapter, a forged Safe and 114.09 ETH

The component attacked is called FlashLoopAdapter and sits at the address 0x16bb8b912da187870c23ec6756bb3fad061283d8. According to SlowMist's analysis, which the firm published on October 2, 2026 via its X channel and which TechFlow Post reproduces verbatim, the access control of that adapter's open() and close() functions could be tricked with a rebuilt Safe contract. The forged contract answered every permission query with a yes. Access control means the checking routine by which a contract decides whether a caller is entitled at all.

A second weakness came on top. The internal _swap() function left the choice of the router and of the call data passed with it to the caller. A router is the contract through which a swap is executed; call data are the instructions sent along with it. Anyone who can determine both freely can redirect a swap into an arbitrary transfer. Combined with the bypassed permission check, that was enough to trigger the module execution in the victim's Safe itself.

Which assets left the contract

What was drained, according to the report by The Crypto Times, was weETH and collateral deposited with Aave. weETH is a liquid restaking token: a receipt for deposited ether that itself remains tradeable and keeps collecting staking income. To release the collateral, the attacker repaid around 1,300 WETH of debt according to SlowMist's assessment. WETH is the token-wrapped form of ether that contracts can process directly.

The operation was financed through a flash loan from Morpho of 11,537 WETH, around 31 million dollars at the rate at the time according to The Crypto Times. A flash loan is a loan without collateral that has to be repaid within the same transaction; if repayment fails, the entire transaction is discarded. Here it was repaid as planned. What was left with the attacker at the end was a profit of 114.09 ETH, about 307,065 dollars at the time of the transaction according to the same source.

The sum is small compared with the large incidents of the year. Measured by the mechanism it is not: the attack needed no stolen key and no signature from the owner. It needed only an activated module.

What the loop module in a Safe actually does: leverage on the staking yield

Looping, sometimes also called leveraged staking, is a cycle of depositing and borrowing. You deposit a liquid staking token as collateral, borrow ether against it, swap the borrowed ether back into the same staking token and deposit again. Every round raises the share that earns income and the debt at the same time. As long as the staking yield sits above the borrowing rate, the surplus grows. If that relationship turns, the interest eats the yield.

Running this cycle several times by hand is expensive and slow. That is why there are helper contracts that bundle all the steps into one transaction. For such a contract to be able to do that for a multisig wallet, it has to be registered as a module. The gain in convenience is real, and the price for it has now appeared on the bill: the module may act without anyone signing.

Abandoned control desk in a dark control room, a red warning light illuminating the row of consoles About twelve hours lay between the transaction and SlowMist's first public warning.

The timeline: transaction on October 1, warning on October 2

The order of events explains why many holders did not notice the incident at first. According to The Crypto Times the transaction was confirmed on October 1, 2026 at 15:08:47 UTC in block 26098264 of the Ethereum blockchain. SlowMist's public warning followed on October 2, 2026 at 02:59 UTC, around twelve hours later. The same report names 0x42c2633438609881c8fBAb82414eb9A0c45F9353 as the attacker address.

Twelve hours is a long time in this situation, and it is no reproach to the analysts. A module call looks on the blockchain like an ordinary transaction from a wallet. There is no alarm bell that rings when a module does something the owner never wanted. Anyone wanting to know whether their Safe is affected has to look into the module list actively.

Why Aave v3 and the Safe core are not affected

This point is easily abbreviated in news reports, and the abbreviation is expensive because it triggers panic in the wrong place. On The Crypto Times' account, the core pools of Aave v3 were not compromised, and the core of the Safe contracts themselves also remained untouched. The flaw sat in the FlashLoopAdapter, a contract outside both systems.

What was open to attack were therefore only Safe wallets that had enabled this adapter as a module. Anyone who deposited ether or weETH directly with Aave without using a loop module was, on this description, not part of the attack surface. Nor was anyone holding through an exchange who has never set up a Safe.

In practice that means a clean dividing line. The question is not whether you use Aave. The question is whether one of your wallets has allowed an external contract to act in its name. That is a property of your wallet, not a property of the protocol.

Module rights in a Safe: where a module replaces your signature

A Safe knows several kinds of permission, and they differ in power. A token approval lets a contract move a certain amount of a certain token. A module goes further: it may trigger transactions in the wallet's name without passing through the signing quorum. A guard, by contrast, restricts what is allowed through at all.

In practice that means a single poorly built module can defeat the whole multi-signature set-up. The three signatures you need for a transfer apply to the normal route. The module takes a different one. The case of October 1 is not the first of its kind; in September a module flaw in another context had already moved a sum in the millions without a signature.

What helps when clearing up, and what does not

An active module can be inspected and removed in the Safe interface under settings. Removing it is itself a transaction and needs the normal number of signatures, so it costs network fees and a little time. Nothing can be recovered that way: funds that have flowed out are gone, even if the module is switched off afterwards. Switching it off prevents the next access, not the last one.

Anyone holding larger amounts long term and running no automated strategies is better served by a wallet whose keys never leave a dedicated device. Which devices do what, and where the differences in handling and recovery lie, is set out in the hardware wallet comparison. For a wallet without modules there is no module flaw.

Hand holding an unbranded hardware wallet with a small display, the thumb resting on the confirmation button What is confirmed one transaction at a time cannot be triggered by an external module in the background.

weETH, looping and liquidation: what hung on the position

The wallets affected held no dormant balances but running loop positions. That matters for placing the case, because two risks hang on a looping position at the same time. One is the interest gap between the staking yield and the borrowing rate. The other is liquidation.

Liquidation means that a lending protocol forcibly sells the deposited collateral as soon as the ratio of debt to collateral breaches a set threshold. With a leveraged cycle that margin is narrow by construction, because every round raises the debt. A price drop of a few percent in the deposited token can then be enough. That an external contract additionally had access in this incident was a third risk on top, one many did not have on their list at all.

For holders in Germany there is a tax point on top that is easily lost in these cycles. Every swap inside the cycle is an event of its own, and every round creates new acquisition dates. Anyone wanting to use the one-year holding period under Section 23 of the German Income Tax Act has to be able to evidence those dates without gaps. An automated module creates exactly such events in larger numbers, and it does so even when you have clicked on nothing yourself.

Statements from Aave and Safe: it stayed quiet into the evening of October 2

According to The Crypto Times' report, no official statements on the incident were available from either Aave or Safe as at publication. Likewise, on this account, no confirmed patch, no pause and no compensation plan had been announced. Advice to switch the module off came from the security community, not from the protocols themselves.

That is less unusual than it sounds, and it has an understandable cause. A flaw in a contract that belongs neither to the protocol nor to the wallet software cannot be fixed from there either. Nobody can switch off an external contract on other people's behalf. For you, though, it means you should not wait for an all-clear from official quarters, because in this constellation it may never come.

For context, the third quarter of 2026 was the most loss-making of the year according to the available assessments. Against the large individual cases of those months, damage of around 307,000 dollars is a footnote. For the two wallets affected it was not, and the attack route via module rights remains open as long as the adapter is active anywhere.

Looping from Germany: the purchase route under MiCA and the holding period

Anyone entering such strategies from Germany makes two decisions that should be kept apart. The first is the purchase route. Since the start of 2026, crypto services in Germany may only be provided by firms authorised under the EU regulation MiCA; the competent supervisor is BaFin. That concerns the route by which you buy and hold ether or a staking token.

The second decision concerns what happens afterwards in your own wallet. A cycle run through a DeFi protocol runs over contracts for which you yourself are the custodian; no authorised service provider is involved there. There is no deposit protection, no complaints body and no provider that makes good a module flaw. The two together give the practical order of play: a regulated purchase route for the holding, and very deliberate decisions about every permission you hand out afterwards.

In tax terms the point made above still stands. Staking income and swap transactions are treated differently, and an automated cycle creates many events that you have to evidence after the fact. Anyone not documenting that as they go will, in case of doubt, not get the holding period recognised.

Aave loop module: What to take away

The situation is manageable and calls for no haste. Three steps make sense, in this order:

  1. Go through the module list in your Safe and remove what is unnecessary. Open the settings in every multisig wallet and look at the modules registered there. Anything you are not actively using goes; removal is a normal transaction with the usual quorum. How wallet types differ in handling, recovery and the granting of rights is shown by the software wallet comparison.
  2. Recalculate any running loop positions. Set the current staking yield against the borrowing rate and look at how far your buffer reaches to the liquidation threshold. Anyone preferring to collect income without leverage will find providers' terms in the overview of staking platforms.
  3. Separate the purchase route from the DeFi part. Leave the holding you only want to hold with a provider authorised under MiCA, and move into the cycle only what you could afford to lose in the worst case. Which houses hold an authorisation is set out in the overview of regulated crypto exchanges.

The core of the incident is no weakness of Aave and none of Safe. It is a reminder that a multi-signature set-up is worth only as much as the list of contracts allowed to bypass it.

(As of October 2, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)