FlashLoopAdapter Safe Module Exploit
A caller-authentication flaw in FlashLoopAdapter, a third-party Safe module that manages Aave v3 leveraged loops, let an attacker forge a Safe and drain roughly $305,000 from two Ethereum wallets.
- Date
- Victim
- FlashLoopAdapter
- Chain(s)
- Status
- Funds Stolen
On October 1, 2026, FlashLoopAdapter — a third-party Safe module that opens and closes Aave v3 leveraged loops for the wallets that enable it — was exploited for roughly $305,000 (about 114 ETH), after an attacker forged a Safe wallet to slip past the module's access checks and drain two Ethereum multisigs.
What happened
FlashLoopAdapter is not part of Aave itself; it is an external contract that a Gnosis Safe can enable to manage leveraged-staking positions. The flaw sat in the access control on the adapter's open() and close() functions, which only asked whether the module was enabled rather than confirming that the caller was a genuine Safe. The attacker deployed a forged Safe contract that always returned true to those checks, then used the module's _swap() path — which accepted an attacker-controlled router and arbitrary calldata — to move funds out. Using a WETH flash loan from Morpho, they repaid roughly 1,335 WETH of Aave debt to unlock the collateral, then withdrew about 1,306.48 weETH from one Safe and 6.4 weETH from a second, keeping around 114 ETH after settling the loan. Security firm SlowMist and the on-chain monitor Defimon Alerts flagged the transactions.
Aftermath
The theft was confined to the two wallets that had enabled the vulnerable module; Aave's core v3 lending contracts were untouched, and founder Stani Kulechov stressed that the compromised code was a third-party adapter built on top of Aave with zero effect on the protocol. No recovery or attacker return has been reported, and the funds remain with the exploiter.
Why it matters
This is the same failure mode that has dogged 2026: the risk living not in a battle-tested core protocol but in the permissioned modules bolted onto Safe multisigs. It echoes the confused-deputy access-control bug in the New Market Trading SquidRouterModule exploit and the signature-bypass in the Gnosis Pay Zodiac Delay Module exploit — in each case the base wallet and the headline protocol were sound, but a helper contract granted sweeping authority on a check that could be spoofed. Enabling a module hands it the power to move a Safe's assets, so an adapter that never verifies its caller is as dangerous as a private key left exposed.
Sources & on-chain evidence
- [01]en.cryptonomist.chhttps://en.cryptonomist.ch/2026/10/02/aave-v3-exploit-flashloopadapter/
- [02]cryptotimes.iohttps://www.cryptotimes.io/2026/10/02/flashloopadapter-exploit-drains-305k-from-two-aave-linked-safes/
- [03]cryptotimes.iohttps://www.cryptotimes.io/2026/10/02/aave-v3-loop-module-hacked-for-114-eth-aaves-pools-not-affected/
- [04]panews.iohttps://panews.io/articles/01a0faa1-55ab-77fc-b694-4000ec063ee6
- [05]crypto-economy.comhttps://crypto-economy.com/aave-v3-unaffected-by-305k-safe-exploit/