Two Ethereum Safe wallets lost approximately $305,000 after an attacker exploited a custom FlashLoopAdapter contract used to manage leveraged Aave v3 positions. The incident was detected at 15:08:57 UTC on October 1, 2026 by Defimon Alerts, with SlowMist publishing its analysis the following day.
The root cause was an access-control flaw in the adapter's open() and close() functions. Instead of verifying a legitimate Safe, the contract checked only whether ISafe(msg.sender).isModuleEnabled(address(this)) returned true. An attacker deployed a fake Safe programmed to return true, passing authentication. The attacker then used the adapter's _swap() function to execute a raw call with attacker-supplied router and calldata, pointing it at a victim Safe and calling execTransactionFromModule.
The attacker took a Morpho WETH flash loan, repaid about 1,335 WETH of Aave debt for the first Safe, freeing roughly 1,306 weETH in collateral, which was withdrawn. A second Safe lost another 6.4 weETH. Both Safes shared the same owner. After repaying the flash loan and converting some assets, the attacker retained around 114.09 ETH, worth approximately $305,000.
Aave founder and CEO Stani Kulechov said the affected contract was a third-party external adapter built on Aave and had “zero effect on Aave v3.” SlowMist identified the attacker address as 0x42c2633438609881c8fBAb82414eb9A0c45F9353 and the vulnerable contract as 0x16bb8b912da187870c23ec6756bb3fad061283d8. The incident highlights risks from Safe modules and integration-layer security, with parallels to a September Safe wallet exploit involving roughly 2,900 rsETH and earlier SquidRouterModule losses.