FlashLoopAdapter exploit drains $305K from two Aave-linked Safe wallets
Image: Crypto.newsOn October 1 2026, an attacker exploited a third-party FlashLoopAdapter module flaw to drain two Ethereum Safe multisig wallets. The attacker forged Safe authentication to bypass the module's access controls, used a Morpho flash loan to repay roughly 1,335 WETH of Aave debt, then withdrew around 1,306 weETH in collateral. Combined losses are estimated at $305K to $310K, with the attacker netting roughly 114.09 ETH. Neither Aave v3 nor Safe core infrastructure was compromised, and both affected wallets disabled the vulnerable module immediately after the attack.
Key points
- A third-party FlashLoopAdapter module flaw allowed an attacker to drain two Safe multisig wallets on Ethereum.
- The attacker forged Safe authentication to bypass the module's access controls.
- Neither Aave v3 nor Safe core infrastructure was compromised in the attack.
- The attacker's net profit from the exploit was approximately 114.09 ETH.
Why it matters
The attack highlights risks from unvetted third-party modules enabled on self-custody wallets. Users who enable external modules on Safe or similar wallets face potential asset loss if those modules have unpatched access control flaws.
Price context · AAVE
At publication
$180.77
Now
$184.84
Change since
+2.25%
7 days · dashed line = publication
Sources · 2 publishers
Crypto.news
Tier 2
FlashLoopAdapter exploit drains $305K from Aave linked Safe wallets
Coverage timeline
- First reported by Crypto Briefing
- Confirmed by Crypto.news
- CryptoVideos brief published
How this brief was made. Our system found this event in 2 independent publications, summarised two complete reports with AI and checked every number above against the source text. Sources are linked in full. Not financial advice. Report an error