TLDR
- An attacker drained about $305,000 from two Ethereum Safe wallets by exploiting a third party contract called FlashLoopAdapter.
- The flaw let a fake Safe contract pass access checks meant only for real wallets.
- The attacker used a Morpho flash loan to repay about 1,335 WETH of Aave debt, then withdrew about 1,306 weETH in collateral.
- Aave founder Stani Kulechov said the adapter was built on top of Aave and had “zero effect on Aave v3.”
- The attacker kept about 114.1 ETH after repaying the flash loan.
A custom contract used to manage leveraged Aave v3 positions on Ethereum has been exploited. Two Safe wallets lost about $305,000 after an attacker got around the contract’s access controls.
The contract, called FlashLoopAdapter, was a third party tool built on top of Aave. It was not part of the core Aave v3 protocol.
Defimon Alerts detected the attack at 15:08:57 UTC on Oct. 1. The monitoring service said Aave v3 itself was not affected.
How the FlashLoopAdapter Exploit Worked
FlashLoopAdapter was a Safe module. Wallets that turned it on could use it to open and close leveraged positions, also called looping strategies, through Aave v3.
Blockchain security firm SlowMist said the flaw was in the access controls for the adapter’s open() and close() functions. The functions only asked the caller whether the module was enabled, instead of confirming the caller was a real Safe.
That gave the attacker an opening. They deployed a fake Safe contract that simply answered “yes” when the adapter ran its check.
Defimon Alerts said later checks during the callback also failed to stop the attack. This was because the attacker’s contract also acted as the flash liquidity provider.
Another function, _swap(), let the caller choose both the swap router and the data sent to it. The attacker set the router to one of the victim Safe wallets and used the data to call execTransactionFromModule, a Safe function that lets an enabled module execute transactions.
Since the victim Safe had already enabled FlashLoopAdapter, the call went through.
Attacker Repaid Aave Debt to Unlock Collateral
The attacker took a WETH flash loan from Morpho. They used it to repay about 1,335 WETH of Aave debt owed by the first Safe.
Repaying the debt freed up the collateral behind the leveraged position. The attacker then made the Safe withdraw about 1,306 weETH to an address they controlled.
A second Safe lost another 6.4 weETH through the same module. Defimon said both wallets had the same single owner.
Part of the weETH was swapped into WETH to pay back the flash loan. Because most of the funds went toward repaying debt, the large withdrawal does not reflect the attacker’s actual profit.
Aave founder and CEO Stani Kulechov said the affected contract was an external adapter and had “zero effect on Aave v3.”
This is not the first Safe module incident this year. In May, an exploit involving the SquidRouterModule took about $3 million to $3.2 million from 86 wallets on Ethereum and Base, and in September, BlockSec traced an attempted exploit of about 2,900 rsETH to weak checks in a contract tied to a Safe module.
SlowMist identified the attacker’s address as 0x42c2633438609881c8fBAb82414eb9A0c45F9353. The firm classified the incident as a smart contract vulnerability.
According to Defimon Alerts, the attacker kept about 114.1 ETH, worth around $305,000 when the incident was reported.



