Hackers exploited a vulnerability in the Loop Safe Module linked to Aave v3, stealing approximately 114 ETH from two multisig wallets by bypassing permission checks with fake Safe wallets.