
A vulnerability in a custom FlashLoopAdapter on Ethereum has resulted in an estimated loss of 114.09 ETH, worth around $305,000, from two Safe wallets. The contract was used to manage leveraged positions through Aave V3.
The attacker bypassed a Safe wallet authentication check and then took out a WETH flash loan through Morpho. The borrowed funds were used to repay Aave debt, which released collateral from a leveraged position. Although approximately 1,306 weETH was withdrawn from one Safe, that figure represents the gross amount moved during the position unwind rather than the attacker’s final proceeds.
Defimon Alerts detected the incident at 15:08:57 UTC on October 1, while SlowMist published its technical analysis on October 2. SlowMist identified a vulnerability in the FlashLoopAdapter’s open and close functions that allowed a malicious contract to impersonate a Safe and satisfy a verification check.
The attacker-controlled contract supplied the adapter with a swap router and calldata. The router was pointed at one of the affected Safes, while the calldata triggered execTransactionFromModule. Since FlashLoopAdapter was already authorized on the wallet, the Safe treated the request as a legitimate module transaction.
The exploit converted an authentication weakness into a way to access wallet-controlled collateral. The incident highlights the risks that can arise from external DeFi integrations, where wallet permissions and transaction execution paths can introduce vulnerabilities even when the underlying lending protocol remains secure.
The attacker used a Morpho WETH flash loan to repay approximately 1,335 WETH of Aave debt tied to the larger Safe. This released collateral supporting its leveraged position and enabled roughly 1,306 weETH to be withdrawn. A second Safe lost approximately 6.4 weETH through the same vulnerable module.
Both affected wallets had the same single owner. After the flash loan was settled and assets were converted, the attacker retained approximately 114.09 ETH, valued by security reports at about $305,000.
The difference between the gross withdrawal and the net loss is important. The 1,306 weETH figure covers collateral transferred during the debt repayment and position unwind. It does not represent the amount ultimately kept by the attacker. The reported net proceeds amounted to about 114.09 ETH.
Aave Says Its Core Protocol Was Not Exploited
Aave founder and CEO Stani Kulechov said the affected contract was an external integration and not part of Aave V3, adding that the incident had “zero effect on Aave v3.”
SlowMist classified the attack as a smart-contract vulnerability, identifying the spoofable Safe check as the key weakness. Defimon described FlashLoopAdapter as a Safe module designed to open and close leveraged Aave V3 positions and estimated the financial impact at roughly $305,000.
The custom FlashLoopAdapter operates on top of Aave V3 and automates leveraged positions for Safes that have enabled it. Safe modules can execute transactions without requiring the wallet owner to approve every action through the standard transaction process. This functionality can improve automation but also introduces additional execution paths that must be secured.
In this incident, the reported flaw was in the adapter’s authentication and execution logic rather than in Safe’s module-permission model. The event therefore points to a vulnerability in the integration layer and does not indicate that Aave V3 lending pools were compromised.
The primary analysis also refers to a separate Safe-wallet incident in September involving about 2,900 rsETH and an authorization weakness in an executor associated with an enabled module. That incident involved different contracts and a distinct attack path.






