Key Takeaways
- FlashLoopAdapter, a specialized module for managing Aave V3 leveraged positions, suffered a security breach on October 1.
- The vulnerability stemmed from an access-control weakness in the custom module, not from Aave’s primary lending infrastructure.
- Two Safe wallets fell victim to the attack, with one losing over 1,300 weETH.
- The exploit incorporated a WETH flash loan borrowed from Morpho during the attack execution.
- Total losses range between $305,000 and $310,000, with the attacker securing approximately 114 ETH.
An Ethereum-based custom module designed for managing leveraged positions on Aave V3 fell victim to a security exploit on October 1. The breach resulted in approximately $305,000 in stolen assets.
The compromised module, known as FlashLoopAdapter, functions as a tool for opening and closing leveraged Aave positions within Safe wallets that have activated the module.
Cybersecurity company Defimon Alerts shared information about the breach through X. According to their analysis, a malicious contract controlled by the attacker successfully circumvented the module’s access verification protocols.
Attack Methodology Breakdown
After bypassing the security checks, the perpetrator leveraged the module’s execution pathway to gain unauthorized access to two Safe wallets. This enabled the extraction of collateral assets from the compromised wallets.
The initial breach involved settling approximately 1,335 WETH in Aave debt obligations. Subsequently, the attacker extracted roughly 1,306.48 weETH from the first Safe wallet.
An additional Safe wallet sustained losses of approximately 6.4 weETH during the same security incident.
Following the extraction, the perpetrator liquidated portions of the stolen assets. According to Defimon’s analysis, they retained approximately 114.1 ETH.
Blockchain records on Etherscan connected to the primary Safe wallet revealed the burning of roughly 1,306.48 variableDebtEthWETH tokens. The data also confirmed the corresponding weETH withdrawal.
Etherscan’s records indicated a gross transaction value of approximately $3.88 million. However, this figure represents the total collateral transferred, not the net financial loss.
Defimon’s $305,000 loss calculation accounts for the actual financial damage after considering the attacker’s initial asset holdings.
Flash Loan Mechanism Utilized
The exploit sequence incorporated a flash loan component. The perpetrator obtained WETH from Morpho as an integral element of the attack strategy.
Flash loans enable contracts to obtain temporary funding within a single transaction cycle. Borrowers must return the principal amount plus applicable fees before transaction completion.
Aave identifies flash loans as a core capability within its V3 lending infrastructure. The utilization of a flash loan mechanism doesn’t inherently indicate a vulnerability in the lending provider.
The identified security gap existed within the custom FlashLoopAdapter contract itself, rather than Aave’s fundamental lending architecture. Aave’s technical documentation identifies borrowing, repayment, withdrawals, and flash loans as integral V3 capabilities.
This incident isn’t an isolated occurrence in 2024. On September 15, another Safe wallet containing a leveraged Aave V3 position was compromised, losing approximately 2,900 rsETH valued at roughly $7.8 million.
During that particular attack, the perpetrator employed a Uniswap V4 hook to transform the position into transferable rsETH. However, an MEV bot named Yoink intercepted the attacker’s transaction through front-running and claimed the assets.
Kelp DAO, the organization managing rsETH, suspended the recipient address following that breach. The team confirmed their core smart contracts and rsETH collateral backing remained unaffected.
Cybersecurity firm SlowMist independently verified the October 1 breach, calculating losses at approximately $310,000 and 114.09 ETH. SlowMist’s analysis indicated the attacker deployed a counterfeit Safe wallet to circumvent authentication mechanisms, then exploited arbitrary transaction data for fund access.
The FlashLoopAdapter security analysis remains ongoing. Authorities have not yet confirmed whether additional wallets or smart contracts were compromised.



