×

FlashLoopAdapter Exploit Targets Two Safe Wallets, Drains $305K

FlashLoopAdapter Exploit Targets Two Safe Wallets, Drains $305K

Two Safe wallets on Ethereum suffered an estimated combined net loss of 114.09 ETH, valued at roughly $305,000, after a custom FlashLoopAdapter used for leveraged Aave V3 positions was exploited.

The attacker defeated a Safe authentication check and then used a Morpho flash loan in WETH to repay Aave debt and release collateral. Approximately 1,306 weETH was withdrawn from one of the affected wallets, but this represents the gross collateral movement during the attack rather than the amount ultimately retained by the attacker.

Defimon Alerts said it detected the exploit at 15:08:57 UTC on October 1. SlowMist published its technical review on October 2, pointing to a weakness in the adapter’s open and close functions. The flaw reportedly allowed a malicious contract to impersonate a Safe and provide a response that passed a check intended to confirm that FlashLoopAdapter had been authorized by the wallet.

The attacker-controlled contract supplied the adapter with both a swap router and calldata. The router was directed to a victim Safe, while the calldata called execTransactionFromModule. Since FlashLoopAdapter had already been enabled on the affected wallet, the Safe processed the request as an authorized module transaction.

This allowed the attacker to turn a narrow authentication weakness into access to collateral controlled by the wallets. The incident illustrates the security risks associated with DeFi integrations, where permissions and transaction-execution routes can create additional attack surfaces beyond the underlying lending protocol.

The attacker took a WETH flash loan from Morpho and used it to repay approximately 1,335 WETH of Aave debt associated with the larger Safe. Once the debt was settled, collateral backing the leveraged position was released, allowing around 1,306 weETH to be withdrawn. The second Safe was also affected, losing approximately 6.4 weETH through the same vulnerable module.

Both wallets had the same single owner. After the flash-loaned funds were repaid and some assets were converted, approximately 114.09 ETH remained with the attacker. Security reports placed the value of those proceeds at around $305,000.

The distinction between the large collateral withdrawal and the reported loss is important. The roughly 1,306 weETH was part of the transaction flow used to repay debt and unwind the leveraged position. It should not be interpreted as the amount stolen. The attacker’s reported net proceeds were approximately 114.09 ETH.

Aave V3 Was Not Directly Affected

Aave founder and CEO Stani Kulechov said the vulnerable component was an external integration rather than an Aave V3 contract. He said the incident had “zero effect on Aave v3.”

SlowMist classified the incident as a smart-contract vulnerability and identified the spoofable Safe verification as the mechanism that allowed the attacker to bypass the intended authorization process. Defimon described FlashLoopAdapter as a Safe module designed to open and close leveraged Aave V3 positions and estimated the loss at approximately $305,000.

FlashLoopAdapter is a custom contract built on Aave V3 to automate leveraged positions for Safes that have enabled the module. Safe modules can execute transactions without requiring the usual owner transaction process for each action. While this supports automation, it also creates another route to wallet assets if the module contains a vulnerability.

The reported weakness was in FlashLoopAdapter’s caller-authentication and execution logic, rather than in the module-permission system itself. As a result, the incident represents a failure at the integration layer and does not indicate that Aave V3’s lending pools were compromised.

The primary analysis also mentions a separate Safe-wallet incident from September involving approximately 2,900 rsETH and an authorization flaw in an executor linked to an enabled module. That case involved different contracts and a separate attack method.

Share this content:

Copyright © 2025 CoinsNewz