FlashLoopAdapter Exploit Drains $305K From Aave-Linked Safe Wallets on Ethereum
A custom DeFi adapter's access control flaw let an attacker use a Morpho flash loan to drain two Safe wallets — Aave v3 itself was unaffected.
3 min read
A custom FlashLoopAdapter contract used to manage leveraged Aave v3 positions was exploited on Ethereum on October 1, 2026, draining approximately $305,000 from two Safe wallets. The attacker bypassed the module's access controls using a Morpho flash loan — but the core Aave v3 protocol was not affected.
Blockchain security firm SlowMist classified the incident as a smart contract vulnerability. Aave founder and CEO Stani Kulechov confirmed the affected contract was a third-party external adapter with "zero effect on Aave v3."
How the attack worked
Defimon Alerts detected the attack at 15:08:57 UTC on October 1. The attacker exploited an authentication flaw allowing a fake Safe wallet to pass checks meant to restrict access to wallets that had enabled the FlashLoopAdapter module.
The attack sequence:
- The attacker took a Morpho WETH flash loan.
- Using borrowed liquidity, they repaid approximately 1,335 WETH of Aave debt belonging to the first affected Safe (0xcfedf95a3653a128dfc2e4288758a1a1850d169f).
- They withdrew roughly 1,306 weETH in collateral from the position.
- Part of the withdrawn weETH was swapped to WETH to settle the flash loan.
- The attacker retained approximately 114.1 ETH, valued at about $305,000.
Third-party risk in DeFi
The incident highlights a persistent DeFi vulnerability: composability creates attack surfaces beyond core protocols. Users interact with Aave through wallets, adapters, and automation modules — each layer adds functionality and risk.
FlashLoopAdapter was a custom contract built on top of Aave, not part of Aave's audited codebase. Users who enabled the module in their Safe wallets trusted its access control logic. That trust was misplaced.
Lessons for DeFi users
Audit the full stack. Using a battle-tested protocol like Aave v3 does not protect you if a third-party adapter has flaws. Review every contract that has permissions on your wallet.
Minimize module permissions. Safe modules with broad access to positions are convenient and dangerous. Treat them like giving someone your private keys with conditions.
Monitor position changes. Automated alerts from firms like Defimon and SlowMist caught this attack in real time. Active monitoring matters when exploits execute in single transactions.
Market context
The exploit occurred during a week of mixed crypto news. NEAR Intents suffered a separate $3.8 million exploit. Bitcoin ETFs saw outflows after a record inflow streak. DeFi security incidents remind participants that smart contract risk is not abstract — it is a line item.
Moving forward
For Aave, the incident reinforces messaging that third-party integrations are not protocol vulnerabilities. For users, it is another data point that DeFi composability requires security analysis at every layer, not just the base protocol.
The $305,000 loss is significant for the affected wallets but modest by DeFi exploit standards. The access control failure pattern — fake wallet passing authentication — is the kind of bug that will recur wherever custom adapters connect to user funds.
More in blockchain
Cubed
Write about the technologies shaping the future.
For developers, founders, and curious minds exploring AI, crypto, Web3, and emerging tech—signal over noise.
One free account across In Plain English, Stackademic, Venture, and Cubed.
How it works- AI, crypto & Web3
- Software & emerging technologies
- Analysis & practical resources
- Thoughtful voices, not hype
Sign in
Google or GitHub
Complete profile
Takes a few minutes
Get approved & publish
Start sharing
Why write for Cubed?
The future deserves thoughtful voices, not just louder headlines.
Comments
Loading comments…