Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerCryptocurrenciesPricingCrypto APIMCPIntegrationsNewsRWA MarketEarnBlogNFTWidgetsDeFi Portfolio TrackerDerivativesETF FlowsCrypto Gaming24h ReportPress KitAPI Docs

Access flaw behind Aave V3 exploit drains over $300,000 from Safe wallets

33m ago•
bullish:

0

bearish:

0

Aave V3 exploit

A custom Ethereum module built to manage leveraged positions on Aave V3 was exploited on October 1, 2026, draining more than $300,000 from two Safe wallets in what security researchers are now calling one of the more technically precise Aave V3 exploit cases of the year. The breach didn’t touch Aave’s core lending contracts at all. Instead, attackers found a crack in a third-party add-on called FlashLoopAdapter, a module designed to open and close leveraged Aave positions for Safe wallet users.

Key takeaways

  • FlashLoopAdapter, a custom Ethereum module for Aave V3 leveraged positions, was exploited on October 1, 2026.
  • More than $300,000 was drained from two Safe wallets, with security firms Defimon Alerts and SlowMist estimating losses between $305,000 and $310,000.
  • The attacker repaid roughly 1,335 WETH in Aave debt, then withdrew about 1,306.48 weETH from one wallet and 6.4 weETH from a second.
  • A WETH flash loan from Morpho was used to carry out the attack, and the attacker kept about 114 ETH afterward.
  • The vulnerability was an access-control flaw in FlashLoopAdapter itself, not in Aave’s underlying lending protocol.

FlashLoopAdapter Exploit Drains Over $300,000 From Safe Wallets

The incident unfolded on October 1 when an attacker-controlled contract managed to slip past the access checks built into FlashLoopAdapter. Security firm Defimon Alerts flagged the activity on X, describing how the module’s execution path let the attacker interact directly with two Safe wallets that had the adapter enabled for leveraged Aave positions.

Details of the October 1, 2026 Exploit

Once inside, the attacker didn’t need to touch Aave’s main lending pool. They simply used FlashLoopAdapter’s own permissions to move collateral out of the wallets it was supposed to be managing safely. That distinction matters: this wasn’t a breach of Aave itself, but of a layer built on top of it.

Amounts Drained and Assets Stolen

In the first wallet, the attacker repaid approximately 1,335 WETH of outstanding Aave debt, a step that unlocked the collateral behind it. They then withdrew about 1,306.48 weETH from that same Safe wallet. A second wallet tied to the same module lost a smaller amount, roughly 6.4 weETH, in the same sequence of transactions.

After the withdrawal, the attacker converted a portion of the stolen assets and ended up holding about 114.1 ETH, according to Defimon’s tracking. An Etherscan record tied to the first wallet showed the burning of roughly 1,306.48 variableDebtEthWETH tokens alongside a matching weETH withdrawal. Etherscan listed the gross transaction value at around $3.88 million, but that figure reflects total collateral moved through the transaction, not the attacker’s actual take. Defimon’s $305,000 estimate, and SlowMist’s close figure of about $310,000, better capture the real financial damage once the flash loan and debt repayment are factored out.

Technical Cause: Access-Control Flaw in FlashLoopAdapter Module

The root cause traces back to how FlashLoopAdapter verified who was allowed to trigger its functions. An attacker-controlled contract passed those checks when it shouldn’t have, opening the door to the entire sequence that followed.

Role of the Access-Control Vulnerability

This is the part of the story that separates a FlashLoopAdapter attack from a genuine Aave protocol failure. Aave’s own documentation lists borrowing, repayment, withdrawals, and flash loans as standard features of its V3 lending pool, and nothing about those core functions broke down here. The weakness lived entirely inside the custom adapter contract that Safe wallet users had opted into for managing leveraged exposure. SlowMist, which independently reviewed the incident, reported that the attacker used a forged Safe wallet to get past authentication, then relied on arbitrary transaction data to reach the funds.

Use of WETH Flash Loan from Morpho

Flash loans are a routine tool in decentralized finance: a contract borrows funds for a single transaction and must repay them, plus a fee, before that transaction closes out. As part of the attack sequence, the attacker took out a WETH loan from Morpho, relying on this borrowed capital to carry out the debt repayment and withdrawal steps without committing any of their own funds. The use of a flash loan on its own isn’t evidence of wrongdoing by the lender; Morpho simply provided a standard, permissionless service that the attacker folded into a broader exploit built around FlashLoopAdapter’s access-control gap.

Investigation Status and Broader Security Context

The FlashLoopAdapter investigation remains open, and it isn’t yet confirmed whether other wallets or contracts tied to the module were affected beyond the two reported so far. That uncertainty is worth sitting with: a Safe wallet vulnerability like this one doesn’t automatically stay contained to the addresses already identified, especially when the flaw sits in shared infrastructure rather than a single user’s configuration.

Ongoing Investigation and Uncertain Impact

Why this matters for the broader DeFi leverage market is straightforward. Safe wallets paired with custom modules have become a common way to manage leveraged positions across lending protocols, and this incident shows that the security of the underlying protocol doesn’t guarantee the security of everything built around it. Aave’s core contracts held up fine throughout the episode, but that offered little comfort to the two wallets whose collateral was drained through a module most users probably assumed was just a convenience layer.

Comparison to Prior Safe Wallet Exploits

This isn’t the first time this year that a leveraged Aave V3 position tied to a Safe wallet has been targeted. A different Safe wallet, which held a leveraged position on Aave V3, lost about 2,900 rsETH on September 15, an amount worth roughly $7.8 million at the time. In that incident, a Uniswap V4 hook was used to turn the position into transferable rsETH, but a bot named Yoink managed to front-run the attacker’s own transaction and claim the funds instead. Kelp DAO, the protocol behind rsETH, paused the receiving address afterward and said its core contracts and the backing for rsETH remained unaffected.

Taken together, the two incidents point to a recurring pattern rather than a one-off accident: the tools layered on top of Aave V3 to make leverage management easier keep turning into the weakest link, even as Aave’s base protocol stays untouched. For anyone running leveraged positions through a Safe wallet module, that’s a distinction worth remembering the next time a headline mentions an Aave V3 exploit — the protocol itself may be fine, but the scaffolding around it is where the risk tends to show up.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

33m ago•
bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.