An exploit targeting a custom FlashLoopAdapter on Ethereum resulted in an estimated net loss of 114.09 ETH, or approximately $305,000, across two Safe wallets. The adapter was built to manage leveraged positions through Aave V3.
The attacker first bypassed a Safe authentication check before using a WETH-denominated flash loan from Morpho to repay debt and unlock collateral. One affected wallet had roughly 1,306 weETH withdrawn, but that amount reflects the overall collateral movement required to unwind the position rather than the attacker’s net proceeds.
Defimon Alerts said the attack was detected at 15:08:57 UTC on October 1. SlowMist’s analysis, published on October 2, identified a weakness in the adapter’s open and close functions. The flaw allowed an attacker-controlled contract to mimic a Safe and return a value that satisfied the adapter’s verification check.
The malicious contract also controlled the swap router and calldata supplied to FlashLoopAdapter. It directed the router to a victim Safe and instructed the wallet to call execTransactionFromModule. Because the adapter was already enabled on the Safe, the transaction was accepted as an authorized module operation.
The exploit demonstrates how a weakness in an external integration can provide access to assets held by a wallet, even when the underlying lending protocol remains unaffected. It also highlights the security importance of wallet permissions and transaction execution routes in DeFi and custody systems.
The attacker used a Morpho flash loan to repay around 1,335 WETH in Aave debt associated with the larger Safe. That repayment released collateral supporting the leveraged position, enabling the withdrawal of approximately 1,306 weETH. The second Safe was affected by the same module and lost about 6.4 weETH.
Both Safes were controlled by the same single owner. Once the flash-loaned funds were repaid and some assets were converted, the attacker retained about 114.09 ETH. Security reports estimated the value of those proceeds at roughly $305,000.
The reported 1,306 weETH withdrawal should not be confused with the final amount lost. It was part of the gross asset flow used to repay debt and close out the leveraged position. The approximately 114.09 ETH remaining after the transactions represents the reported net proceeds.
Aave V3 Lending Pools Remain Unaffected
Aave founder and CEO Stani Kulechov said the exploited component was an external integration rather than an Aave V3 contract, adding that the incident had “zero effect on Aave v3.”
SlowMist described the event as a smart-contract vulnerability and traced the exploit to the spoofable Safe verification check. Defimon said FlashLoopAdapter functions as a Safe module for opening and closing leveraged Aave V3 positions and estimated the loss at about $305,000.
FlashLoopAdapter is a custom contract built around Aave V3 that automates leveraged positions for participating Safes. Safe modules can execute wallet transactions without requiring the usual owner-driven transaction process for every action. While this enables automation, a compromised or vulnerable module can create an additional path to wallet-held assets.
The issue identified in this attack was the adapter’s authentication and execution logic, rather than Safe module permissions themselves. The incident therefore concerns the integration layer and does not indicate that Aave V3’s core lending pools were compromised.
A separate Safe-wallet incident reported in September also involved an authorization weakness and an enabled module, with approximately 2,900 rsETH affected. However, that case involved different contracts and a separate attack mechanism.





