How could the contract get whitelisted if not because insider

. Yet another case where multisig is working great but the guys behind the multisig are the problem.And yet when such exploit happens, AAVE always take the hit with the bad debt from the exploit which is getting borrowed against.
From another news, look at this :
The most significant detail so far comes from ExVul’s follow-up timeline. According to ExVul, the vault owner’s Safe, a multisignature (multisig) smart contract wallet that requires several approvals for each transaction, removed the attacker contract from the whitelist at 08:52 UTC. One minute later, at 08:53 UTC, the same Safe re-enabled it.
ExVul said both administrative transactions showed three successful Elliptic Curve Digital Signature Algorithm (ECDSA) signature recoveries under the same signing identities. In simple terms, the changes carried valid approvals from the Safe’s existing signers. The first borrow came about 70 seconds after the contract was re-enabled.
This places the focus on how those approvals were obtained, rather than on a flaw in Aave or in the vault’s lending logic. Whether the signers’ keys were compromised, a signing process was manipulated, or another failure occurred has not been confirmed by any party.
sourceThe attacker contract got removed only to get whitelisted again 1 minute later.
