Advertisement

FlashLoopAdapter Attack Drains $305,000 From Two Safe Wallets

Two Safe wallets on Ethereum lost an estimated 114.09 ETH, worth about $305,000, after a custom FlashLoopAdapter designed to manage leveraged Aave V3 positions was exploited.

The attacker circumvented a Safe authentication mechanism before taking a Morpho WETH flash loan to repay debt and release collateral. One of the wallets saw roughly 1,306 weETH withdrawn, although that amount reflects the gross collateral movement during the transaction sequence and not the attacker’s final gain.

Defimon Alerts said it identified the attack at 15:08:57 UTC on October 1. SlowMist published its investigation on October 2, pointing to a flaw in the adapter’s open and close functions. The weakness allowed a malicious contract to impersonate a Safe and return the expected response, defeating a check intended to verify that FlashLoopAdapter had been legitimately enabled by the wallet.

The attacker-controlled contract supplied both the swap router and transaction calldata to the adapter. It directed the router toward a victim Safe and used calldata to trigger execTransactionFromModule. Because the FlashLoopAdapter was already enabled on that Safe, the wallet processed the request as an authorized module transaction.

That authentication flaw ultimately provided a route to collateral held by the affected wallets. The incident demonstrates why DeFi security depends not only on lending protocols but also on the permissions, integrations and transaction-execution mechanisms surrounding them.

The attacker used a Morpho WETH flash loan to repay about 1,335 WETH in Aave debt linked to the larger Safe. Once the debt was repaid, the collateral backing the leveraged position became available, allowing approximately 1,306 weETH to be withdrawn. The second affected Safe lost around 6.4 weETH through the same vulnerable module.

The two Safes shared a single owner. Following repayment of the flash loan and conversions of some assets, the attacker ended up with approximately 114.09 ETH, which security researchers valued at roughly $305,000.

The distinction between the collateral withdrawn and the eventual loss is significant. The 1,306 weETH figure describes a gross transaction flow used to unwind the leveraged position and settle the debt. It does not represent the amount ultimately retained by the attacker. The reported net proceeds were approximately 114.09 ETH.

Aave V3 Contracts Were Not Affected

Aave founder and CEO Stani Kulechov said the vulnerable component was an external integration rather than an Aave V3 contract, stating that the incident had “zero effect on Aave v3.”

SlowMist categorized the event as a smart-contract vulnerability and attributed the exploit to the ability to bypass the Safe verification mechanism. Defimon identified FlashLoopAdapter as a Safe module built for opening and closing leveraged Aave V3 positions and put the estimated loss at approximately $305,000.

The FlashLoopAdapter is a custom contract operating on top of Aave V3 for leveraged positions held in Safes that have authorized the module. Safe modules can execute transactions without going through the wallet owner’s standard transaction flow each time. This enables automation but also creates an additional route to assets when a module contains a security flaw.

The reported problem was not the existence of module permissions itself. Instead, the vulnerability was located in the adapter’s authentication and transaction-execution logic. As a result, the incident points to a failure in the integration layer rather than a compromise of Aave V3’s lending pools.

The primary report also mentions another Safe-wallet incident from September involving roughly 2,900 rsETH and an authorization weakness in an executor linked to an enabled module. That event involved separate contracts and a different exploitation path.