📈 Get daily crypto insights that make you smarter about your money

FlashLoopAdapter Exploit Drains 305000 USD From Aave Linked Safe Wallets

A custom smart contract module used to manage leveraged Aave v3 positions has been exploited on Ethereum, draining an estimated 305,000 USD from two Safe wallets and once again highlighting the risks that third-party adapters introduce on top of otherwise audited protocols.

The attacker bypassed access controls in the FlashLoopAdapter contract, according to an analysis by blockchain security firm SlowMist, ultimately walking away with roughly 114.09 ETH. The incident was detected by Defimon Alerts at 15:08:57 UTC on Oct. 1.

Aave itself was not affected

A critical distinction in this incident: the exploited contract was a third-party adapter built on top of Aave, not part of the core Aave v3 protocol. Aave founder Stani Kulechov confirmed that the affected contract was a third-party adapter and that the exploit had zero effect on Aave v3 itself.

FlashLoopAdapter operated as a Safe module for opening and closing leveraged looping positions through Aave v3. Safes that enabled the module could use it to manage strategies involving borrowed assets and collateral. The vulnerability lived in how the adapter decided who was allowed to call it.

How the spoofed Safe attack worked

According to SlowMist, the weakness was in the access controls of the adapter’s open() and close() functions. Instead of independently verifying that the caller was a legitimate Safe wallet, the functions simply checked whether ISafe(msg.sender).isModuleEnabled(address(this)) returned true.

An attacker could deploy a fake Safe contract programmed to always return true when FlashLoopAdapter made that check. Once the fake Safe passed the test, the attacker gained access to functionality intended only for authorized wallets. Defimon Alerts noted that checks performed during the callback did not stop the malicious transaction, because the attacker’s contract also acted as the flash liquidity provider.

A second function, _swap(), compounded the problem. It allowed a raw call to a swapRouter using caller-supplied swapCalldata — both of which the attacker controlled. Rather than pointing to an ordinary swap router, the attacker set the router address to one of the victim Safe wallets, with calldata instructing it to call execTransactionFromModule, a Safe function that lets an enabled module execute a transaction. Because FlashLoopAdapter was already enabled by the victim Safe, the call was accepted and the wallet’s funds were exposed.

The mechanics of the drain

The attack was more sophisticated than a simple transfer out of the compromised wallets. Defimon Alerts said the attacker took a WETH flash loan on Morpho and used the borrowed liquidity to repay approximately 1,335 WETH of Aave debt belonging to the affected positions. With the debt cleared, the attacker withdrew roughly 1,306 weETH in collateral through the manipulated module, according to the security firm’s reconstruction of the exploit chain.

After unwinding the loop and settling the flash loan, the attacker retained approximately 114.09 ETH in profit. SlowMist published the root-cause breakdown on Oct. 2, and the incident quickly circulated among DeFi security researchers as a textbook example of a spoofable interface check.

A recurring pattern for Safe modules

The incident is not isolated. A similar problem involving permissions attached to Safe modules surfaced in September, when an Ethereum Safe wallet exploit involving roughly 2,900 rsETH was traced by BlockSec to weak authorization checks in an executor contract connected to an enabled Safe module. In that case, an MEV bot front-ran the attempted exploit and captured the assets before the original attack transaction reverted.

The pattern is consistent: the Safe proxy architecture itself held up, but ancillary contracts trusted callers too readily. Modules that verify identity by asking the caller to vouch for itself — rather than checking state the module controls or expects — remain a persistent attack surface.

Lessons for DeFi users

For users of leveraged strategies, the takeaway is that enabling any third-party module on a Safe wallet extends that module’s attack surface to the entire balance it can reach. Adapter contracts built by independent developers may offer convenient looping, but they do not inherit the audits, bug bounties or battle-tested history of the underlying protocols they wrap.

DeFi watchers also note the speed of detection and transparency around the incident — public root-cause analyses from both SlowMist and Defimon Alerts appeared within hours — as a sign the ecosystem’s incident-response culture continues to mature, even as the exploits themselves keep coming.

11 thoughts on “FlashLoopAdapter Exploit Drains 305000 USD From Aave Linked Safe Wallets”

  1. third party adapter gets drained for 305k and every headline still leads with Aave-linked. stani had to clarify the core protocol was untouched, rough look for aave PR wise

    1. checking isModuleEnabled on msg.sender without verifying its an actual Safe is wild. that bug class is smart contract 101 stuff

      1. checking isModuleEnabled on msg.sender without verifying the caller is a real Safe, that is week one material. adapters need their own audit, inherited trust counts for nothing

      2. yep and this is exactly why safes ship a module registry in the first place. people still bolt unknown adapters onto multisigs holding real funds, then act surprised

  2. 114 eth haul, small money, but the pattern repeats forever. people enable random modules on their Safe without reading a line of the code

  3. 305k drained from a safe module and half of twitter will still blame aave. read the article, the adapter was third party, core v3 untouched

      1. 114 eth is pocket change by 2026 standards but its like the sixth safe adapter exploit this quarter. at this point the pattern IS the exploit

        1. sixth one this quarter is the real stat. the module registry cant help when people enable adapters from a pinned discord message

  4. SlowMist says the attacker bypassed access controls. Same pattern every time: the protocol is fine, someone’s custom looping wrapper eats it.

  5. SlowMist pinning it on a missing Safe verification in under a day is the only decent news here. Whoever audited that FlashLoopAdapter wrapper owes some people 305k though.

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$84,758.00-0.2%ETH$2,683.85-0.6%SOL$119.58+1.0%BNB$773.39+0.1%XRP$1.500.0%ADA$0.2502-0.1%DOGE$0.0945-0.3%DOT$1.21+2.5%AVAX$11.03+0.7%LINK$14.13-1.2%UNI$8.95-1.8%ATOM$1.71-0.5%LTC$69.74+3.1%ARB$0.2018+0.4%NEAR$4.79-2.1%FIL$1.04+1.1%SUI$1.16-1.9%BTC$84,758.00-0.2%ETH$2,683.85-0.6%SOL$119.58+1.0%BNB$773.39+0.1%XRP$1.500.0%ADA$0.2502-0.1%DOGE$0.0945-0.3%DOT$1.21+2.5%AVAX$11.03+0.7%LINK$14.13-1.2%UNI$8.95-1.8%ATOM$1.71-0.5%LTC$69.74+3.1%ARB$0.2018+0.4%NEAR$4.79-2.1%FIL$1.04+1.1%SUI$1.16-1.9%
Scroll to Top