Two Safe multisignature wallets lost approximately 114.09 ETH after an attacker exploited an access-control flaw in FlashLoopAdapter, a third-party module used to manage leveraged positions on Aave V3. According to SlowMist’s technical analysis, the October 1 attack abused the adapter’s authentication logic before unwinding the victims’ positions with flash-loaned liquidity. The vulnerability affected FlashLoopAdapter rather than Aave V3’s core lending contracts or Safe’s underlying multisig system.
The attack was executed in a single Ethereum transaction. FlashLoopAdapter’s open() and close() functions checked whether ISafe(msg.sender).isModuleEnabled(address(this)) returned true, effectively asking the caller itself to confirm that the adapter was authorized. An attacker-controlled contract could impersonate a Safe and simply return true, passing a security check that did not independently establish the caller’s legitimacy.
🚨SlowMist TI Alert🚨
💸 @aave v3 Loop Safe Module Loss: ~114.09 ETH
🔍 Root Cause: FlashLoopAdapter's open()/close() access control only checks ISafe(msg.sender).isModuleEnabled(address(this)), which is spoofable via a fake Safe that always returns true. Its _swap() then…
— SlowMist (@SlowMist_Team) October 2, 2026
Fake Safe Opened a Privileged Execution Path
Passing the initial check became more dangerous because FlashLoopAdapter’s swap mechanism accepted a caller-supplied swapRouter and calldata. The attacker pointed that execution path toward victim Safes that had legitimately enabled FlashLoopAdapter and invoked execTransactionFromModule. Once a Safe grants a module execution authority, vulnerable module logic can move wallet assets without satisfying the Safe’s normal owner-signature threshold for each transaction.
A Morpho WETH flash loan supplied liquidity to unwind the leveraged positions. Roughly 1,335 WETH of Aave debt was repaid, releasing collateral that included approximately 1,306.48 weETH from the larger position and another 6.4 weETH from a second Safe. After swaps and repayment of the borrowed liquidity, the attacker retained approximately 114.09 ETH, meaning the multimillion-dollar collateral movement should not be added to the final loss estimate.
That security boundary closely resembles the earlier SquidRouterModule exploit that drained Safe wallets. In that incident, another externally enabled module provided the vulnerable execution path while Squid’s production router remained unaffected. Both cases demonstrate that a multisig’s effective security perimeter includes every module that has been delegated authority, not only the wallet’s signature threshold.
Aave and Safe Core Infrastructure Remained Intact
Aave founder Stani Kulechov said the exploited adapter was an external contract built on top of Aave and had no effect on Aave V3 itself. The available technical analysis similarly does not identify a failure in Safe’s base contracts. The victims were exposed because their wallets had specifically authorized the vulnerable FlashLoopAdapter, narrowing the incident to an integration-level compromise.
That distinction has become increasingly important across DeFi. Persistent permissions were central to a recent Magic Eden-related exploit involving legacy wallet approvals, while a CoW Swap DNS compromise exposed users through frontend infrastructure even though its settlement contracts remained intact. A functioning base protocol does not eliminate risks introduced by modules, approvals, routers or interfaces layered around it.
After the FlashLoopAdapter exploit, the stolen ETH was consolidated and security monitoring subsequently traced transfers toward Tornado Cash. The wallet owners also sent an onchain proposal allowing the attacker to retain 11.41 ETH as a 10% bounty if 102.69 ETH was returned by October 3. No confirmed recovery has been publicly established in the material available as of October 5, leaving the approximately 114 ETH drain unresolved despite the attempted negotiation.
The incident ultimately exposes a narrow but consequential authorization failure: the attacker did not break Aave, Safe or Ethereum, but exploited code that the affected wallets had already trusted to act on their behalf. For modular DeFi setups, delegated execution rights can turn a flaw in auxiliary software into direct access to collateral even when every underlying protocol behaves as designed.
