Aave-Linked Safe Wallets Lose $305K
- An attacker drained about $305,000 from two Ethereum Safe wallets on Oct. 1 after exploiting an access-control flaw in FlashLoopAdapter.
- The attacker used a Morpho flash loan to repay debt and unlock collateral before withdrawing about 1,312.88 weETH total.
- Aave founder Stani Kulechov confirmed that the incident involved a third-party contract and had no effect on Aave v3.
An attacker drained about $305,000 from two Ethereum Safe wallets on Oct. 1 after exploiting an access-control flaw in FlashLoopAdapter, a third-party module used to manage leveraged Aave v3 positions.
The incident did not affect Aave v3 itself. Security researchers identified the weakness in the external adapter’s authentication logic, which allowed a malicious contract to impersonate an authorized Safe and execute transactions through wallets that had enabled the module.
Fake Safe Bypassed FlashLoopAdapter Authentication
FlashLoopAdapter lets Safe wallets open and close leveraged positions on Aave v3. Its open() and close() functions checked whether the calling contract reported that the adapter was enabled without separately confirming that the caller was a legitimate Safe.
The attacker deployed a fake Safe that returned the expected approval response. SlowMist said the adapter also accepted caller-controlled router and transaction data, allowing the attacker to invoke execTransactionFromModule against victim wallets and move assets without owner authorization.
Morpho Flash Loan Unlocked 1,306.48 WeETH
The attacker used a Morpho WETH flash loan to repay about 1,335 WETH of Aave debt held by the larger Safe. Clearing the debt unlocked the wallet’s collateral, allowing roughly 1,306.48 weETH to be withdrawn to an attacker-controlled address.
A second Safe lost about 6.4 weETH through the same module. After repaying the flash loan and converting part of the withdrawn assets, the attacker retained about 114.09 ETH, valued near $305,000 when the incident was reported.
Aave Says Core V3 Contracts Were Unaffected
Aave founder Stani Kulechov said FlashLoopAdapter is a third-party contract built on top of Aave and that the incident had no effect on Aave v3. Security researchers also identified the adapter, rather than Aave’s lending contracts, as the vulnerable component.
Two affected Safe wallets had been identified when the exploit was disclosed. The incident highlights the security risk of external wallet modules that retain permission to execute transactions after they are enabled.