An attacker drained about 114.09 ETH, worth over $300,000, from two Safe multisig wallets through a flaw in FlashLoopAdapter, a third-party tool used with Aave v3 lending positions. Blockchain security firm SlowMist said on Oct. 2 that the attacker bypassed the adapter’s authentication checks, executed calls through the affected wallets and withdrew collateral. Roughly 1,300 WETH of debt was repaid during the attack to unlock collateral tied to the positions; that repayment was not the amount stolen.
Why it matters
SlowMist traced the entry point to the adapter’s open() and close() functions. Their check that a Safe had enabled the adapter as a module could be spoofed with a fake Safe contract that always returned a positive answer. The attacker then used the adapter’s ability to accept a caller-specified router and calldata to direct a call back to a victim Safe. Because the adapter was already an enabled module on that wallet, the call could invoke Safe’s execTransactionFromModule function and move collateral, including weETH.
Aave founder Stani Kulechov said the flaw was in an external adapter, not Aave v3’s core smart contracts, and had “zero effect on Aave v3.” The distinction matters for a lending protocol with more than $33 billion in total value locked: an integration can expose its users even when the underlying protocol remains intact.
Market impact
The reported direct loss is about 114.09 ETH across two wallets, not a loss from Aave v3’s core contracts. The immediate exposure appears limited to users of the vulnerable adapter. The outstanding question is whether other wallets enabled the same module and hold positions that could be reached through the flaw.
Frequently asked questions
-
Was Aave v3 itself exploited?
No. Aave founder Stani Kulechov said the incident involved FlashLoopAdapter, a third-party tool built on Aave, and did not affect Aave v3’s core smart contracts.
-
How did the attacker bypass FlashLoopAdapter’s authentication?
SlowMist said a fake Safe contract returned a positive response to the adapter’s check that the calling wallet had enabled it as a module.
-
How did the adapter flaw let the attacker move collateral?
The attacker supplied a router and calldata that directed an external call back to a victim Safe. FlashLoopAdapter was already an enabled module there, allowing the call to execute a wallet transaction.
-
Was the 1,300 WETH debt repayment part of the amount stolen?
No. SlowMist estimated the direct loss at about 114.09 ETH. It said roughly 1,300 WETH of debt was repaid during the attack to unlock collateral.
-
Which wallets face potential exposure from this flaw?
The reported exploit affected two Safe multisig wallets using the vulnerable adapter. It remains unclear whether other wallets enabled the same module.
CryptoSlate