Spoofed Safe Check Drains 114.09 ETH From Ethereum (ETH) FlashLoopAdapter
An attacker spoofed a Safe check in FlashLoopAdapter to drain 114.09 ETH, about $305,000, from two Safe wallets holding leveraged Aave V3 positions.
AI SummaryAI
- FlashLoopAdapter exploit drained 114.09 ETH, about $305,000, from two Safe wallets on October 1.
- SlowMist attributed the theft to a spoofable Safe authentication check in the adapter's open() and close() functions.
- A Morpho flash loan repaid 1,335 WETH of Aave debt, unlocking roughly 1,306 weETH in collateral.
- A second Safe lost about 6.4 weETH through the same enabled module.
Spoofed Safe Check Unlocks the Module
The failure began in a permission check, not in a lending pool. FlashLoopAdapter, a custom contract built to open and close leveraged leverage loops on Aave V3, requires each caller to prove that a legitimate Safe wallet has enabled the adapter as a module. On Thursday, October 1, a malicious contract passed that check by posing as a Safe and returning the expected value, and two wallets that had enabled the module paid with a combined 114.09
Ethereum (ETH), roughly $305,000 at the Ethereum price of the incident. On-chain monitoring placed the first attack transaction at 15:08:57 UTC on October 1, and the security firm SlowMist published a security alert the next day, Friday, October 2, attributing the bypass to a spoofable authentication weakness in the adapter's open() and close() functions. The firm classified the incident as a smart-contract vulnerability rather than a compromise of any lending market. The amounts are small by exploit standards, but the path the attacker took is not.
The mechanics were narrow but effective. The attacker-controlled contract also supplied the adapter's swap router and calldata, pointed the router at a victim Safe, and set the calldata to invoke execTransactionFromModule, the function through which a Safe module executes transactions from the wallet address of the Safe itself. Because FlashLoopAdapter was already enabled on that Safe, the wallet treated the call as an authorized module transaction and moved collateral without any owner signature. Neither Aave's lending pools nor the Safe standard itself were faulted; the flaw sat in the adapter's caller-authentication and execution logic, a reminder that Safe modules support automation by design but also hand an enabled module a direct route to the assets a wallet controls. No attacker address or fund-recovery plan has been disclosed so far.
Flash Loan Unwind, Gross Versus Net
The attacker financed the unwind with a flash loan denominated in WETH from Morpho, a loan that is borrowed and repaid inside a single transaction. About 1,335 WETH went to repay Aave debt tied to the larger Safe's looped position; the repayment freed the collateral, and roughly 1,306 weETH was withdrawn from that wallet. A second Safe lost about 6.4 weETH through the same module. The withdrawal figure is gross transaction flow, not the attacker's take: after the borrowed funds were settled and some assets converted, approximately 114.09
Ethereum (ETH) remained with the attacker, an amount valued at about $305,000. Reading the 1,306 weETH as the stolen sum would overstate the loss by a wide margin. Both affected Safes shared the same single owner, so the entire net loss fell on one operator's position-management setup. Transaction records on the Ethereum mainnet show each step in sequence, from the loan opening to the final conversion.
A loop position repeats deposit and borrow steps to enlarge exposure on Aave V3, which is why unwinding it means repaying debt before collateral can move. Aave founder and CEO Stani Kulechov addressed the case in an official post on October 2, writing that the vulnerable component was an external third-party adapter built on top of Aave with “zero effect on Aave v3.” The V3 pools kept operating through the episode, and no loss inside the lending market itself has been reported. The record also notes a separate September Safe-wallet incident involving roughly 2,900 rsETH and weak authorization in a different executor connected to an enabled module; that case involved distinct contracts and a different attack path, and only the October event traces to FlashLoopAdapter.
Where the Post-Mortem Draws the Line
COINOTAG's reading: the evidence trail here is unusually complete. SlowMist's post-mortem pins the root cause to the spoofable Safe check inside the adapter, and the founder's official statement places the fault at the integration layer rather than inside Aave V3. On-chain, every figure checks out against the transaction records: 1,335 WETH of debt repaid, about 1,306 weETH of collateral moved as gross flow, and 114.09
Ethereum (ETH) retained as net proceeds. The same failure reaches only Safes running this adapter; Aave's pools and the Safe standard sit outside the scope the sources set. Operators with similar leverage modules enabled are left with one practical question: does the module verify who is calling, or does it trust a returned value?
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

