Blockchain AcademicsBlockchain Academics
FlashLoopAdapter Exploit Drains $305K From Two Ethereum Safe Wallets

FlashLoopAdapter Exploit Drains $305K From Two Ethereum Safe Wallets

A vulnerability in the FlashLoopAdapter module enabled attackers to drain approximately $305,000 from two Safe wallets on Ethereum using leveraged Aave V3 positions. Aave's core contracts remained secure.

Blockchain Academics NewsroomEdited by Ibrahim RajabOctober 2, 20262 min read
Share

FlashLoopAdapter Exploit Drains $305K From Two Ethereum Safe Wallets

A security flaw in the FlashLoopAdapter module drained approximately $305,000 from two Safe wallets on Ethereum on October 2, using leveraged Aave V3 positions to execute the attack. Aave confirmed its core contracts were not compromised.

The FlashLoopAdapter is a third-party module designed to enable leveraged positions on Aave V3, the lending protocol with billions in total value locked (TVL, the sum of assets deposited into a protocol). By sitting between a user's Safe wallet and Aave's lending infrastructure, the module introduces an additional layer of smart contract code beyond what Aave's audited core contracts govern. That integration layer is where the attacker found an opening.

Two Safe wallets were targeted. The attacker exploited the module's logic to manipulate the leveraged Aave V3 positions those wallets held, ultimately siphoning the funds. Safe wallets that had no interaction with FlashLoopAdapter were unaffected.

"Aave says its core contracts were unaffected."

Aave, via statement

The distinction matters. Aave V3 currently holds tens of billions in TVL across its deployments, and a vulnerability in the core protocol would carry systemic consequences for DeFi. This attack did not touch that infrastructure. The loss of $305,000, while material to the two affected wallet holders, represents a negligible fraction of Aave's total deposits and does not signal a flaw in the lending protocol itself.

The incident reflects a broader pattern in DeFi security: composability risk. DeFi protocols are designed to interoperate, with third-party modules, adapters, and integrations stacking on top of audited base contracts. Each additional layer expands the attack surface. Safe, formerly Gnosis Safe, is one of the most widely used multisignature wallet frameworks in the space. Its module system, which allows users to extend wallet functionality, has been a recurring target for attackers who exploit add-on logic rather than the core vault.

No patch details or post-mortem timeline have been published as of this writing. Users holding Aave positions through custom Safe modules should verify whether FlashLoopAdapter is enabled on their wallets and consider disabling it until a full incident report is available.

Discussion

Loading comments...