An attacker exploited the custom FlashLoopAdapter contract on Ethereum linked to leveraged Aave V3 positions, draining about $305,000 from two Safe wallets.

Defimon Alerts detected the attack at 15:08:57 UTC on Thursday, October 1, 2026.

SlowMist later found an access control flaw that allowed the attacker to bypass the adapter’s wallet checks.

The attacker used a fake Safe contract to pass an authorization check meant for legitimate wallets.

FlashLoopAdapter allows Safe wallets to manage leveraged positions through Aave V3.

However, the adapter could not reliably confirm that the caller represented a genuine Safe wallet.

The attacker exploited that weakness and gained access to transaction functions reserved for authorised wallets.

The flaw affected the adapter rather than Aave V3’s core lending contracts.

The attacker then supplied the swap router and transaction data for the malicious transaction.

They directed the router toward a victim Safe and used transaction data that triggered a module transaction.

FlashLoopAdapter already had permission to operate on the victim wallet. The Safe therefore accepted the transaction as an authorised action from the enabled module.

Debt Repayment Unlocks Safe Collateral

The attacker used a Morpho WETH flash loan to repay about 1,335 WETH of Aave debt linked to the first Safe.

The repayment released collateral supporting the wallet’s leveraged position.

The attacker then withdrew about 1,306 weETH from the Safe and transferred it to an address under their control.

The attacker used part of the withdrawn assets to settle the flash loan.

The same FlashLoopAdapter flaw also affected a second Safe wallet. The attacker took about 6.4 weETH from the second wallet through the vulnerable module.

Defimon Alerts said both affected Safes shared the same single owner. The attacker also converted part of the withdrawn collateral during the transaction.

The large collateral withdrawal did not represent the attacker’s final proceeds. The transaction included debt repayment and flash loan settlement before the attacker completed the operation.

Defimon Alerts estimated that the attacker retained about 114.1 ETH after the transaction. SlowMist later estimated the remaining amount at about 114.09 ETH.

Aave V3 Was Not Affected

SlowMist estimated the victims’ net loss at about $305,000 and classified the incident as a smart contract vulnerability.

The security firm linked the loss to FlashLoopAdapter’s access controls and transaction execution logic.

The reported loss reflects the assets that remained with the attacker after the debt repayment and other transaction costs.

The attack therefore involved a smaller final gain than the gross collateral moved during the transaction.

Aave founder and CEO Stani Kulechov said the affected contract was an external adapter rather than an Aave V3 contract.

SlowMist and Defimon Alerts did not identify a vulnerability in Aave V3’s core contracts during their analysis.

Both reports instead linked the losses to the custom adapter’s authentication and transaction execution logic.

Share.
Leave A Reply