Choose Rich Live
Crypto News

Third-party Aave adapter exploit drains 114 ETH from two Safe wallets

An attacker exploited FlashLoopAdapter, a third-party lending tool built on Aave, stealing about 114 ETH from two Safe multisig wallets, according to security firm SlowMist.

Aave founder Stani Kulechov speaking with a microphone while seated on a panel
Image: @CoinGapeMedia

An attacker exploited a third-party lending adapter built on Aave to drain about 114.09 ether (ETH), valued at over $300,000, from two Safe multisig wallets, according to blockchain security firm SlowMist. The incident targeted FlashLoopAdapter, an external tool used with Aave v3 positions, leaving Aave's core protocol unaffected.[6][2][8][3]

SlowMist traced the incident to access-control flaws in FlashLoopAdapter's open() and close() functions, which verified whether the calling Safe had enabled the module. The attacker bypassed this check by deploying a fake Safe contract that consistently returned positive responses. FlashLoopAdapter also allowed callers to specify the router address and calldata for external contract calls. By directing the router toward the victims' Safe wallets, the attacker invoked Safe's execTransactionFromModule function to withdraw weETH and collateral after repaying roughly 1,300 wrapped ether (WETH) in debt to unlock the positions.[6][2][4]

Aave founder Stani Kulechov stated that the incident did not involve Aave v3's core smart contracts and had zero effect on the underlying lending protocol. SlowMist noted that other wallets utilizing the same FlashLoopAdapter module may still remain exposed.[6][7][1][5]

Key facts

  • FlashLoopAdapter, a third-party lending adapter built on Aave, was exploited to steal about 114.09 ETH from two Safe multisig wallets.
  • The exploit targeted access-control vulnerabilities within the open() and close() functions of FlashLoopAdapter.
  • The attacker spoofed module authentication checks using a fake Safe contract and redirected calldata to execute transactions via the victims' Safes.
  • Approximately 1,300 WETH in debt was repaid during the exploit to unlock protected collateral before draining weETH and other assets.
  • Aave founder Stani Kulechov stated that Aave v3 core contracts were not involved and the main protocol was unaffected.
  • SlowMist warned that other wallets that enabled the vulnerable FlashLoopAdapter module could still be at risk.

Sources · 8 sources

  1. CO

    CoinGape@CoinGapeMediaPost on X ·

    🚨 UPDATE: @aave founder Stani Kulechov says the $310K exploit flagged by SlowMist targeted a third-party adapter built on #Aave, not Aave V3 itself, which remains unaffected. https://t.co/jorB4KzJt7

    Open source
  2. WB

    Wu Blockchain@WuBlockchainPost on X ·

    SlowMist: Aave v3 Loop Safe Module Exploited, Approximately 114.09 ETH Stolen SlowMist issued a security alert stating that Aave v3 Loop Safe Module was exploited through an access-control vulnerability in FlashLoopAdapter’s open() and close() functions. The attacker allegedly bypassed Safe authorization and executed arbitrary modules to steal approximately 114.09 ETH from two Safe multisig addresses, while repaying around 1,300 WETH in debt to unlock collateral.

    Open source
  3. CT

    Coin TelegraphArticle ·

    Aave founder says V3 unaffected after third-party adapter exploit drains $305K Aave founder Stani Kulechov said Aave v3 was unaffected after an attacker exploited a third-party adapter to drain about $305,000 from two Safe multisig wallets.

    Open source
  4. CN

    crypto.news@cryptodotnewsPost on X ·

    BREAKING: Aave V3’s Safe Module loses 114 ETH in an access control exploit The attacker abused a flaw in FlashLoopAdapter’s open and close functions to bypass Safe authorization, repay about 1,300 WETH in debt and unlock the protected collateral. https://t.co/bbKrJd1x0X

    Open source
  5. CO

    Cointelegraph@CointelegraphPost on X ·

    🚨 UPDATE: Aave founder Stani Kulechov says the $310K exploit flagged by SlowMist hit a third-party adapter built on top of Aave, not Aave v3 itself, which remains unaffected. https://t.co/jirlDAHvpM

    Open source
  6. CR

    CryptoSlateArticle ·

    Crypto hackers exploit third-party Aave tool to steal 114 ETH A third-party lending adapter built on Aave was exploited to steal about 114 ETH, worth over $300,000, while the protocol itself remained unaffected. On Oct. 2, blockchain security firm SlowMist said the attacker compromised two Safe multisig wallets through a flaw in the FlashLoopAdapter used with Aave v3 positions. The exploit allowed the attacker to bypass the adapter’s authentication checks, execute arbitrary calls, and drain collateral from the affected wallets. SlowMist estimated the direct loss at about 114.09 ETH. It said roughly 1,300 WETH of debt was also repaid during the attack to unlock collateral tied to the positions. Aave founder Stani Kulechov said the incident did not involve Aave v3’s core smart contracts. He said : “This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.” The distinction is significant for Aave, the largest decentralized lending protocol, with more than $33 billion in total value locked. The exploit affected infrastructure layered on top of Aave. Fake Safe bypass opened access to collateral SlowMist traced the vulnerability to the FlashLoopAdapter’s open() and close() functions, which checked whether the calling Safe had enabled the adapter as a module. That verification could be spoofed. Related Reading Why DeFi giant Aave is pulling the plug on six hyped blockchains making less than $5,000 a quarter According to SlowMist, the attacker created a fake Safe contract that always returned a positive response when asked whether the module was enabled. The adapter then accepted the forged authentication and proceeded to its internal swap function. The more serious weakness came next. The adapter allowed the caller to specify both the router and calldata used in an external contract call. The attacker pointed the router back at the victim Safe and supplied instructions invoking Safe’s execTransactionFromModule function. Because the FlashLoopAdapter was already enabled as a module on the affected wallets, that call gave the attacker a path to execute transactions through the victims’ Safes. SlowMist said the technique was used to withdraw weETH and collateral associated with Aave positions from two multisig wallets. The incident highlights a recurring risk in decentralized finance: protocol security can remain intact while integrations built around it create separate attack surfaces. For Aave, the immediate exposure appears contained to users of the vulnerable adapter. The next question is whether other wallets enabled the same module and whether the adapter’s developers identify additional affected positions before attackers can reuse the same authentication flaw. The post Crypto hackers exploit third-party Aave tool to steal 114 ETH appeared first on CryptoSlate .

    Open source
  7. CR

    CryptoSlate@CryptoSlatePost on X ·

    SlowMist says a third-party Aave adapter exploit drained about 114 ETH from two Safe wallets. Aave v3’s core contracts were unaffected. Other wallets using the same vulnerable module may still be exposed. https://t.co/Zih5pS049U

    Open source
  8. TB

    The Block@TheBlockCoPost on X ·

    NEW: SlowMist flagged that a Safe module used for Aave v3 loops was exploited for roughly 114.09 ETH ($310,000). The attacker reportedly forged Safe authentication and repaid about 1,300 WETH in debt to unlock collateral before draining assets from two multisigs. https://t.co/SSvR0qEOLD

    Open source