FlashLoopAdapter Exploit Drains $305K from Aave-Linked Safe Wallets

1 hour ago 3 sources negative

Key takeaways:

  • DeFi integration-layer flaws like FlashLoopAdapter pose hidden risks to Safe users holding weETH on Aave.
  • Aave v3's isolation may reassure AAVE holders, but third-party modules remain a persistent attack vector.
  • Watch Safe module approvals and weETH collateral as integration exploits may spur short-term deleveraging.

Two Ethereum Safe wallets lost approximately $305,000 after an attacker exploited a custom FlashLoopAdapter contract used to manage leveraged Aave v3 positions. The incident was detected at 15:08:57 UTC on October 1, 2026 by Defimon Alerts, with SlowMist publishing its analysis the following day.

The root cause was an access-control flaw in the adapter's open() and close() functions. Instead of verifying a legitimate Safe, the contract checked only whether ISafe(msg.sender).isModuleEnabled(address(this)) returned true. An attacker deployed a fake Safe programmed to return true, passing authentication. The attacker then used the adapter's _swap() function to execute a raw call with attacker-supplied router and calldata, pointing it at a victim Safe and calling execTransactionFromModule.

The attacker took a Morpho WETH flash loan, repaid about 1,335 WETH of Aave debt for the first Safe, freeing roughly 1,306 weETH in collateral, which was withdrawn. A second Safe lost another 6.4 weETH. Both Safes shared the same owner. After repaying the flash loan and converting some assets, the attacker retained around 114.09 ETH, worth approximately $305,000.

Aave founder and CEO Stani Kulechov said the affected contract was a third-party external adapter built on Aave and had “zero effect on Aave v3.” SlowMist identified the attacker address as 0x42c2633438609881c8fBAb82414eb9A0c45F9353 and the vulnerable contract as 0x16bb8b912da187870c23ec6756bb3fad061283d8. The incident highlights risks from Safe modules and integration-layer security, with parallels to a September Safe wallet exploit involving roughly 2,900 rsETH and earlier SquidRouterModule losses.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.