Aave-Linked Safe Wallets Lose $305K
TECHNOLOGY

Aave-Linked Safe Wallets Lose $305K

Image Credit: Shutterstock

An attacker drained about $305,000 from two Ethereum Safe wallets on Oct. 1 after exploiting an access-control flaw in FlashLoopAdapter, a third-party module used to manage leveraged Aave v3 positions.

The incident did not affect Aave v3 itself. Security researchers identified the weakness in the external adapter’s authentication logic, which allowed a malicious contract to impersonate an authorized Safe and execute transactions through wallets that had enabled the module.

Fake Safe Bypassed FlashLoopAdapter Authentication

FlashLoopAdapter lets Safe wallets open and close leveraged positions on Aave v3. Its open() and close() functions checked whether the calling contract reported that the adapter was enabled without separately confirming that the caller was a legitimate Safe.

The attacker deployed a fake Safe that returned the expected approval response. SlowMist said the adapter also accepted caller-controlled router and transaction data, allowing the attacker to invoke execTransactionFromModule against victim wallets and move assets without owner authorization.

Morpho Flash Loan Unlocked 1,306.48 WeETH

The attacker used a Morpho WETH flash loan to repay about 1,335 WETH of Aave debt held by the larger Safe. Clearing the debt unlocked the wallet’s collateral, allowing roughly 1,306.48 weETH to be withdrawn to an attacker-controlled address.

A second Safe lost about 6.4 weETH through the same module. After repaying the flash loan and converting part of the withdrawn assets, the attacker retained about 114.09 ETH, valued near $305,000 when the incident was reported.

Aave Says Core V3 Contracts Were Unaffected

Aave founder Stani Kulechov said FlashLoopAdapter is a third-party contract built on top of Aave and that the incident had no effect on Aave v3. Security researchers also identified the adapter, rather than Aave’s lending contracts, as the vulnerable component.

Two affected Safe wallets had been identified when the exploit was disclosed. The incident highlights the security risk of external wallet modules that retain permission to execute transactions after they are enabled.

More For You

Explore More News