A third-party Safe module used to manage leveraged Aave V3 positions was exploited on Ethereum, leaving two multisignature wallets with losses of approximately 114.09 ETH. The attack occurred on October 1 and was disclosed by security researchers the following day. The affected component was FlashLoopAdapter, not Aave V3’s core lending contracts, making the security boundary central to understanding the incident.
According to a technical analysis from ExVul, the vulnerability involved the access-control logic protecting the adapter’s open() and close() functions. SlowMist’s incident database similarly attributed the attack to spoofed Safe authentication. The adapter trusted ISafe(msg.sender).isModuleEnabled(address(this)) as evidence that the caller was authorized, even though an attacker-controlled contract could be programmed to always return true.
🚨 ALERT — FlashLoopAdapter Safe-module exploit on Ethereum
Two Safes using a custom Aave v3 loop adapter lost an estimated $305K. The attacker gained 114.092 ETH after gas in one transaction. Aave v3 itself was not affected.
Root cause:
FlashLoopAdapter trusted a…— ExVul (@exvulsec) October 1, 2026
Spoofed Safe Authentication Opened the Execution Path
Once the attacker bypassed that check, the adapter’s swap logic provided another critical path. SlowMist said the attacker could control the swapRouter and associated calldata, then use the module execution path against Safes that had previously enabled FlashLoopAdapter. Because enabled Safe modules can execute transactions with delegated authority, compromised module logic can become a direct path to wallet assets without defeating the Safe’s normal owner-signature threshold.
The attacker also used a Morpho WETH flash loan as part of the transaction sequence. Roughly 1,300 WETH of Aave V3 debt was repaid to unlock collateral, after which weETH was withdrawn from the affected positions. That debt repayment was an intermediate step in unwinding the leveraged positions and should not be added to the approximately 114.09 ETH loss figure. SlowMist values the resulting loss at about $305,000.
The distinction resembles the earlier SquidRouterModule exploit that affected Safe wallets, where delegated permissions in an external module rather than the underlying protocol became the attack surface. In both cases, the relevant trust boundary extended beyond the core application into software that had been granted authority to act from a Safe. This is different from an exploit of Aave’s lending pools, Ethereum consensus or Safe’s base multisig contracts.
Third-Party Modules Extend the DeFi Security Perimeter
Safe modules are designed to add automation and specialized execution capabilities, but those permissions also increase the amount of code that can influence wallet assets. A secure base wallet does not eliminate risk introduced by an enabled module with flawed authorization logic. Similar boundary problems have appeared elsewhere in DeFi, including legacy wallet approvals that remained exploitable after an application stopped using the affected contract and frontend infrastructure compromises that left core smart contracts untouched.
The FlashLoopAdapter incident is particularly instructive because the attacker did not need to compromise Aave V3 itself. Instead, the exploit combined a caller-controlled authentication response with an adapter already trusted by the victim wallets. The available evidence therefore supports a narrow conclusion: two Safe wallets using the vulnerable adapter were drained, while no compromise of Aave V3’s core contracts has been established.
The episode also reinforces why security assessments need to map every privileged component surrounding a DeFi position. Legacy routers, modules, approvals and auxiliary contracts can remain capable of moving assets even when the underlying protocol is functioning as designed, as another deprecated-router exploit demonstrated earlier this year. For leveraged Safe setups, the effective security perimeter is therefore the complete execution stack granted wallet authority, not only the lending protocol beneath it.
