An attacker exploited an access-control flaw in the third-party FlashLoopAdapter contract on October 1, 2026, draining approximately $305,000 from two Ethereum Safe wallets. The vulnerability allowed a fake Safe contract to bypass authentication checks. Using a Morpho flash loan, the attacker repaid 1,335 WETH of Aave debt to unlock and withdraw over 1,306 weETH in collateral, retaining a net profit of 114.09 ETH. Aave founder Stani Kulechov confirmed that the core Aave v3 protocol was unaffected.
Story comments
Loading comments…