Stani Kulechov: The Aave v3 contract is not affected, indicating a third-party adapter vulnerability
Aave founder Stani Kulechov stated that the third-party external adapter built on top of Aave v3 was utilized, and the Aave v3 contract itself was not affected. The FlashLoopAdapter involved in the Aave v3 Loop Safe module has open() and close() access control vulnerabilities. The attacker forged Safe authentication and executed arbitrary modules, stealing 114.09 ETH from two Safe multi signature addresses and repaying 1300 WETH debts to unlock collateral.