Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Aave exploit drains $305,000 through third-party adapter vulnerability
00

Aave exploit drains $305,000 through third-party adapter vulnerability

Oct 2, 2026

An exploit targeting a third-party adapter on October 1, 2026, drained approximately 114.09 ETH, valued up to $310,000, from two Safe multisig wallets belonging to a single owner. The attacker bypassed authentication checks in the FlashLoopAdapter module using a spoofed Safe contract, then utilized a Morpho flash loan to repay Aave debt and unlock collateral. Aave founder Stani Kulechov confirmed that the incident had zero impact on core Aave V3 contracts, highlighting risks associated with external integrations.

Execution and financial impact of the exploit

  • ▪The FlashLoopAdapter exploit was executed in a single transaction, where the attacker repaid approximately 1,300 to 1,335 WETH of Aave debt to withdraw roughly 1,306 weETH in collateral
  • ▪The October 1, 2026 FlashLoopAdapter exploit drained two Safe wallets belonging to a single owner, resulting in an estimated net loss of 114.09 ETH, valued between $305,000 and $310,000
  • ▪Following the October 1, 2026 FlashLoopAdapter exploit, the stolen 114.09 ETH was transferred to a central address and subsequently moved in batches toward the non-custodial privacy mixer Tornado Cash
  • ▪An attacker exploited the third-party FlashLoopAdapter contract on October 1, 2026, using a Morpho WETH flash loan to repay debt and unlock collateral from two Safe wallets

Technical mechanism of the vulnerability

  • ▪The FlashLoopAdapter vulnerability allowed an attacker in the October 1, 2026 exploit to supply a malicious swap router and calldata, invoking execTransactionFromModule to execute unauthorized transactions through the victim Safes
  • ▪The FlashLoopAdapter exploit was made possible by an access-control vulnerability in the adapter's open() and close() functions, which failed to properly validate caller-supplied responses
  • ▪Safe modules can execute wallet transactions without requiring standard owner signatures, meaning a bug in an enabled module such as FlashLoopAdapter can grant attackers a direct route to wallet assets
  • ▪The attacker behind the October 1, 2026 FlashLoopAdapter exploit bypassed its authentication check by deploying a fake Safe contract that spoofed the module-enabled check and returned a positive response

Reactions and mitigation measures

  • ▪Blockchain security firms SlowMist and ExVul both raised alerts following the October 1, 2026 FlashLoopAdapter exploit
  • ▪Following the October 1, 2026 FlashLoopAdapter exploit, the owner of the two affected Safe wallets disabled the FlashLoopAdapter module to prevent further financial losses

Debatable claims

  • ▪Core DeFi protocols are responsible for the security of their third-party integration ecosystems
  • ▪Flash loans do more harm than good to the DeFi ecosystem
  • ▪DeFi users bear the primary responsibility for vetting third-party wallet integrations
  • ▪DeFi users should avoid enabling third-party automation modules on multisig wallets

4 sources

Cointelegraph
Aave V3 Unaffected After Third-Party Adapter Exploit Drains $305K
View source article
Crypto News
Aave Hack: FlashLoopAdapter Hits Two Safe Wallets
View source article
CoinPedia
Aave-Linked Exploit Drains $305K in ETH From Safe Wallet
View source article
Crypto Briefing
Aave v3 exploit drains up to $310K after Safe module attack
View source article

Story comments

Loading comments…

Related entities

Ethereum

Related Projects

AaveSafeAave V4

Topics

Smart contractsCrypto hacksEthereumDeFiDeFi security