FlashLoopAdapter Hits Two Safe Wallets

Author

Ahmed Barakat

Author

Ahmed Barakat

Part of the Team Since

Mar 2024

About Author

Ahmed Barakat is a journalist and copywriter based in Georgia with a growing focus on blockchain technology, DeFi, AI, privacy, digital assets, and fintech innovation.


Fact Checked by

CryptoNews Editorial Team

Author

CryptoNews Editorial Team

Part of the Team Since

Sep 2018

About Author

The CryptoNews editorial team is composed of seasoned writers specializing in cryptocurrency and blockchain technology. Their expertise ensures comprehensive, accurate, and insightful content for…

Last updated: 

A custom FlashLoopAdapter used to manage leveraged Aave V3 positions was exploited in a hack on Ethereum, leaving two Safe wallets with an estimated net loss of 114.09 ETH, or about $305,000.

The attacker spoofed a Safe authentication check, then used a Morpho WETH flash loan to repay debt and unlock collateral. The roughly 1,306 weETH withdrawn from one wallet was a gross transaction flow, not the attacker’s net proceeds.

Read More:  Everything XRP Holders Need to Know About Ripple Swell 2026

Defimon Alerts said it detected the Ethereum attack at 15:08:57 UTC on Thursday, October 1. SlowMist published its analysis on Friday, October 2, identifying a weakness in the adapter’s open and close functions. A malicious contract could pose as a Safe and return that value, passing a check intended to confirm that a legitimate wallet had enabled FlashLoopAdapter.

The AAVE hack attacker-controlled contract also supplied the adapter’s swap router and calldata. It pointed the router at a victim Safe and set the calldata to invoke execTransactionFromModule. Because FlashLoopAdapter was already enabled on that Safe, the wallet accepted the call as an authorized module transaction.

The sequence turned a narrow authentication flaw into access to wallet-controlled collateral. The episode underscores how wallet permissions and execution paths matter alongside the security of the lending protocol itself, a concern also central to custody infrastructure and authentication controls.

Read More:  83% Europe Crypto Firms Have No MiCA Licenses: July 1 Deadline

Earn $50 and Enter $300K Prize Draw on EdgeX

Flash Loan Hack Repaid Aave Debt Before Collateral Was Withdrawn

The attacker used a Morpho flash loan denominated in WETH to repay approximately 1,335 WETH of Aave debt associated with the larger Safe. Repayment freed collateral tied to its leveraged position, allowing roughly 1,306 weETH to be withdrawn. A second Safe lost about 6.4 weETH through the same vulnerable module.

Both affected Safes had the same single owner. After the borrowed funds were settled and some assets converted, the attacker retained approximately 114.09 ETH, which security reports valued at about $305,000.

The distinction between gross movement and realized loss is material. The large collateral withdrawal enabled the debt repayment and position unwind; it should not be read as the amount stolen. The reported net proceeds were the ETH remaining after those transaction steps.

Trade AAVE on Bybit and Get a Chance to Win Our $1,000 USDT Airdrop

Read More:  Collector Faces Trial Over $55 Million Hack

Aave Says Core Contracts Not Affected

Aave founder and CEO Stani Kulechov said the vulnerable component was an external integration rather than an Aave V3 contract and had “zero effect on Aave v3.”

SlowMist classified the incident as a smart-contract vulnerability and attributed the bypass to the spoofable Safe check. Defimon described FlashLoopAdapter as a Safe module for opening and closing leveraged Aave V3 loops and estimated the loss at approximately $305,000.

FlashLoopAdapter is a custom contract built on Aave V3 for managing leveraged positions in Safes that enabled it. Safe modules can execute wallet transactions without requiring the standard owner transaction flow each time, which supports automation but also gives an authorized module a route to wallet assets.

Here, the module’s permission was not itself the reported bug; the adapter’s caller-authentication and execution logic were. The case is therefore a DeFi security failure at the integration layer, not evidence that Aave V3’s lending pools were compromised.

The primary source also notes a separate September Safe-wallet incident involving roughly 2,900 rsETH and weak authorization in an executor connected to an enabled module, but the two incidents involved distinct contracts and attack paths.

Discover: The Best Token Presales


Facebook Comments Box

Related

Tragic Road Accident in Mymensingh Kills 7 Auto-Rickshaw Passengers

Seven auto-rickshaw passengers have been killed in a tragic...

Solana enters US banking with 90 North Dakota banks leading it

North Dakota’s banks and credit unions are getting a...

Electrum patches Lightning flaw, but old Bitcoin backups break

Electrum’s latest security update fixes a Lightning backup defect,...