SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen

Blockchain safety agency SlowMist has issued an alert after the Aave v3 Loop Safe module was exploited by means of an access-control vulnerability, ensuing within the lack of roughly 114.09 ETH (round $305,000) from two Safe multisignature wallets. The assault, detected on October 1 by Defimon Alerts, focused the FlashLoopAdapter contract however left the core Aave v3 protocol untouched.
FlashLoopAdapter is a Safe module designed to automate the opening and shutting of leveraged positions on Aave v3. According to SlowMist, the basis reason for the exploit lay within the entry controls of the adapter’s `open()` and `shut()` capabilities. Rather than independently verifying the caller’s id, the capabilities merely checked that `ISafe(msg.sender).isModuleEnabled(handle(this))` returned true. An attacker may subsequently deploy a pretend Safe contract programmed to all the time return true, permitting the malicious caller to go the verification verify.
The attacker then exploited the module’s `_swap()` perform, which executes a uncooked name to a caller-supplied router with totally attacker-controlled calldata. By setting the router to a sufferer Safe handle and the calldata to `execTransactionFromModule` — a Safe perform that lets an enabled module execute transactions — the attacker successfully turned the adapter’s personal permissions right into a distant management over the victims’ wallets. Because FlashLoopAdapter was already enabled as a module on each focused Safes, the ensuing calls have been accepted with out challenge.
The assault chain concerned greater than merely draining out there balances. The attacker took a Morpho WETH flash mortgage and used the borrowed funds to repay roughly 1,335 WETH of Aave debt belonging to the bigger pockets, recognized as 0xcfedf95a3653a128dfc2e4288758a1a1850d169f.
Repaying the debt unlocked the leveraged place’s collateral, after which the attacker had the Safe withdraw roughly 1,306 weETH to an attacker-controlled handle. A second Safe, 0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520, misplaced a further 6.4 weETH by means of the identical mechanism. Defimon Alerts famous that each wallets shared the identical single proprietor. After settling the flash mortgage and changing a part of the withdrawn collateral to WETH, the attacker retained round 114.1 ETH. The attacker handle was recognized as 0x42c2633438609881c8fBAb82414eb9A0c45F9353, whereas the susceptible contract sits at 0x16bb8b912da187870c23ec6756bb3fad061283d8.
Aave v3 core unaffected, echoing earlier Safe module incidents
In response to the incident, Aave founder and CEO Stani Kulechov clarified in a put up that the exploited code was not a part of Aave v3 itself however a third-party exterior adapter constructed on high of the protocol, with zero impact on the core contracts. Neither safety alert recognized any vulnerability in Aave v3, which continued to function usually.
The exploit nonetheless highlights a recurring sample within the Safe ecosystem. Because modules are granted the flexibility to execute transactions from a pockets with out going by means of the usual proprietor approval stream, a single flaw in a module’s authentication logic can expose all belongings beneath its management. The same weak point surfaced in September, when an Ethereum Safe exploit involving roughly 2,900 rsETH was traced to insufficient authorization checks in an executor contract tied to an enabled module. In May, attackers drained roughly $3 million from 86 wallets by abusing the SquidRouterModule, and Gnosis Pay customers have been individually urged to withdraw funds after a flaw was present in its Zodiac delay module.
The put up SlowMist: Aave v3 Loop Safe Module Exploited Via Access Control Flaw, 114.09 ETH Stolen appeared first on Metaverse Post.

SlowMist TI Alert
Root Cause: FlashLoopAdapter’s open()/shut() entry management solely checks ISafe(msg.sender).isModuleEnabled(handle(this)), which is spoofable through a pretend Safe that all the time returns true. Its _swap() then…