News linked to both this project and an event.
according to monitoring by Stani Kulechov, Aave founder Stani Kulechov stated that what was exploited was a third-party external adapter built on top of Aave v3, and the Aave v3 contracts themselves were not affected. The FlashLoopAdapter in the Aave v3 Loop Safe module involved had access control vulnerabilities in its open() and close() functions. The attacker forged Safe authentication and arbitrary module execution to steal approximately 114.09 ETH from two Safe multisig addresses, and repaid approximately 1,300 WETH in debt to unlock collateral.
SlowMist has issued a security alert stating that a vulnerability has been discovered in the Aave V3 Loop Safe Module. Attackers exploited forged Safe authentication and arbitrary Module execution to steal approximately 114.09 ETH from two Safe multisig wallets.The attackers bypassed authentication by forging a Safe that always returns true, and leveraged an arbitrarily controllable router and calldata to execute module transactions, transferring weETH and Aave collateral. The attackers repaid approximately 1,300 WETH in debt to unlock the collateral.
Odaily News Bitcoin contributor Jameson Loop and other cryptographers have proposed an initiative that could force Bitcoin holders to migrate their tokens to new quantum-resistant addresses, otherwise their tokens would be permanently frozen by the network itself. In this scenario, holders would technically still "own" the coins but would lose the ability to transfer them. This is known as Bitcoin Improvement Proposal BIP-361, which was updated in Bitcoin's official proposal repository on Tuesday under the title "Post-Quantum Migration and Legacy Signature Deprecation".BIP-361 builds upon the BIP-360 proposal introduced in February. BIP-360 introduced a soft fork (a network upgrade) designed to enable a new transaction type called "Pay-to-Merkle-Root" (P2MR). This method draws from Bitcoin's Taproot (P2TR) framework but removes the key-based spending path, thereby eliminating an element widely considered to be at risk in the quantum era.The BIP-361 proposal divides the migration into three phases. Phase A begins three years after activation, prohibiting anyone from sending new Bitcoin to legacy, quantum-vulnerable addresses. You can still spend from these addresses but cannot receive any coins.Phase B begins five years after activation, rendering legacy signatures (ECDSA and Schnorr) completely invalid. The network will reject any attempts to spend coins from quantum-vulnerable wallets. Essentially, your coins will be frozen.Finally, there is Phase C, a still-under-research rescue plan: holders of frozen wallets may be able to prove ownership via zero-knowledge proofs (a method of proving knowledge of a secret without revealing the secret itself). If successful, coins frozen in Phase B could be recovered. (CoinDesk)