What's Hot

    Countries working out of room to cushion power shock impression, UNDP warns | Invesloan.com

    October 2, 2026

    Two Safe Wallets Lose $305,000 in FlashLoopAdapter Attack | Invesloan.com

    October 1, 2026

    Bond yields immediately retreat from latest highs as consumers step again into the Treasury market | Invesloan.com

    October 1, 2026
    Facebook Twitter Instagram
    Finance Pro
    Facebook Twitter Instagram
    invesloan.cominvesloan.com
    Subscribe for Alerts
    • Home
    • News
    • Politics
    • Money
    • Personal Finance
    • Business
    • Economy
    • Investing
    • Markets
      • Stocks
      • Futures & Commodities
      • Crypto
      • Forex
    • Technology
    invesloan.cominvesloan.com
    Home » Two Safe Wallets Lose $305,000 in FlashLoopAdapter Attack | Invesloan.com
    Crypto

    Two Safe Wallets Lose $305,000 in FlashLoopAdapter Attack | Invesloan.com

    October 1, 2026Updated:October 1, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A custom FlashLoopAdapter used to manage leveraged Aave V3 positions was exploited in a hack on Ethereum, leaving two Safe wallets with an estimated net loss of 114.09 ETH, or about $305,000.

    The attacker spoofed a Safe authentication check, then used a Morpho WETH flash loan to repay debt and unlock collateral. The roughly 1,306 weETH withdrawn from one wallet was a gross transaction flow, not the attacker’s net proceeds.

    SlowMist: Aave v3 Loop Safe Module Exploited, Approximately 114.09 ETH Stolen

    SlowMist issued a security alert stating that Aave v3 Loop Safe Module was exploited through an access-control vulnerability in FlashLoopAdapter’s open() and close() functions. The attacker allegedly… pic.twitter.com/a97iMcGWnI

    — Wu Blockchain (@WuBlockchain) October 2, 2026

    Defimon Alerts said it detected the Ethereum attack at 15:08:57 UTC on Thursday, October 1. SlowMist published its analysis on Friday, October 2, identifying a weakness in the adapter’s open and close functions. A malicious contract could pose as a Safe and return that value, passing a check intended to confirm that a legitimate wallet had enabled FlashLoopAdapter.

    The AAVE hack attacker-controlled contract also supplied the adapter’s swap router and calldata. It pointed the router at a victim Safe and set the calldata to invoke execTransactionFromModule. Because FlashLoopAdapter was already enabled on that Safe, the wallet accepted the call as an authorized module transaction.

    The sequence turned a narrow authentication flaw into access to wallet-controlled collateral. The episode underscores how wallet permissions and execution paths matter alongside the security of the lending protocol itself, a concern also central to custody infrastructure and authentication controls.

    Earn $50 and Enter $300K Prize Draw on EdgeX

    Flash Loan Hack Repaid Aave Debt Before Collateral Was Withdrawn

    Aave (AAVE)
    24h7d30d1yAll time

    The attacker used a Morpho flash loan denominated in WETH to repay approximately 1,335 WETH of Aave debt associated with the larger Safe. Repayment freed collateral tied to its leveraged position, allowing roughly 1,306 weETH to be withdrawn. A second Safe lost about 6.4 weETH through the same vulnerable module.

    Both affected Safes had the same single owner. After the borrowed funds were settled and some assets converted, the attacker retained approximately 114.09 ETH, which security reports valued at about $305,000.

    A FlashLoopAdapter hack on Ethereum caused an estimated $305,000 net loss for two Safe wallets, while Aave says its core contracts unaffected.

    The distinction between gross movement and realized loss is material. The large collateral withdrawal enabled the debt repayment and position unwind; it should not be read as the amount stolen. The reported net proceeds were the ETH remaining after those transaction steps.

    Trade AAVE on Bybit and Get a Chance to Win Our $1,000 USDT Airdrop

    Aave Says Core Contracts Not Affected

    Aave founder and CEO Stani Kulechov said the vulnerable component was an external integration rather than an Aave V3 contract and had “zero effect on Aave v3.”

    This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.

    — Stani (@StaniKulechov) October 2, 2026

    SlowMist classified the incident as a smart-contract vulnerability and attributed the bypass to the spoofable Safe check. Defimon described FlashLoopAdapter as a Safe module for opening and closing leveraged Aave V3 loops and estimated the loss at approximately $305,000.

    FlashLoopAdapter is a custom contract built on Aave V3 for managing leveraged positions in Safes that enabled it. Safe modules can execute wallet transactions without requiring the standard owner transaction flow each time, which supports automation but also gives an authorized module a route to wallet assets.

    Here, the module’s permission was not itself the reported bug; the adapter’s caller-authentication and execution logic were. The case is therefore a DeFi security failure at the integration layer, not evidence that Aave V3’s lending pools were compromised.

    The primary source also notes a separate September Safe-wallet incident involving roughly 2,900 rsETH and weak authorization in an executor connected to an enabled module, but the two incidents involved distinct contracts and attack paths.

    Discover: The Best Token Presales

    The post Two Safe Wallets Lose $305,000 in FlashLoopAdapter Attack appeared first on Cryptonews.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Keep Reading

    Bitcoin Price Prediction: Understanding and Predicting 2026 Uptober | Invesloan.com

    Vault Access and Interest Rules at Center of XRPL Lending Vote | Invesloan.com

    Anthropic IPO Polymarket Betting Odds of 2026 IPO Hit 82% | Invesloan.com

    Dogecoin Price: Can DOGE Hit $1 as DogeOS Testnet Goes Live? | Invesloan.com

    Perplexity AI Predicts a Bullish Finish to 2026 for XRP USD | Invesloan.com

    XRP News: $1.49B Unlock Leaves Net Supply Unclear | Invesloan.com

    China Crypto Future: Solana Co. CEO Joseph Chee on Regulation | Invesloan.com

    Stacks Crypto Erupts Overnight as STX Price Surges +30% | Invesloan.com

    The Ethena Crypto Buyback Math Puts the $2 ENA Target to the Test | Invesloan.com

    LATEST NEWS

    Countries working out of room to cushion power shock impression, UNDP warns | Invesloan.com

    October 2, 2026

    Two Safe Wallets Lose $305,000 in FlashLoopAdapter Attack | Invesloan.com

    October 1, 2026

    Bond yields immediately retreat from latest highs as consumers step again into the Treasury market | Invesloan.com

    October 1, 2026

    Bitcoin Price Prediction: Understanding and Predicting 2026 Uptober | Invesloan.com

    October 1, 2026
    POPULAR

    China’s first passenger jet completes maiden commercial flight

    May 28, 2023

    Numbers taking US accountancy exams drop to lowest level in 17 years

    May 29, 2023

    Toyota chair faces removal vote over governance issues

    May 29, 2023
    Advertisement
    Load WordPress Sites in as fast as 37ms!
    Facebook Twitter Pinterest WhatsApp Instagram
    © 2007-2023 Invesloan.com All Rights Reserved.
    • Privacy
    • Terms
    • Press Release
    • Advertise
    • Contact

    Type above and press Enter to search. Press Esc to cancel.

    invesloan.com
    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}