An exploit targeting a third-party adapter on October 1, 2026, drained approximately 114.09 ETH, valued up to $310,000, from two Safe multisig wallets belonging to a single owner. The attacker bypassed authentication checks in the FlashLoopAdapter module using a spoofed Safe contract, then utilized a Morpho flash loan to repay Aave debt and unlock collateral. Aave founder Stani Kulechov confirmed that the incident had zero impact on core Aave V3 contracts, highlighting risks associated with external integrations.
Story comments
Loading comments…