0x579935565799…57993553
Attacker Drains Two Safe Multisigs for $310K via Aave Module Flaw
An attacker forged Safe authentication on the FlashLoopAdapter to drain two multisigs of up to $310K, netting 114.09 ETH after repaying ~1,300 WETH of Aave debt via a Morpho flash loan.
Outputs
Two Safe multisigs drained of $305K–$310K on Ethereum on October 1, 2026, via the third-party FlashLoopAdapter module
Attacker used a Morpho WETH flash loan to repay ~1,300 WETH of Aave debt, seizing ~1,306.48 WETH of collateral and netting ~114.09 ETH in a single transaction
Flaw traced to weak caller validation in the module's open() and close() functions; Aave v3 and Safe core were not compromised, and both Safes disabled the module after SlowMist and ExVul alerts
An attacker drained two Safe multisig wallets on Ethereum on October 1, 2026, exploiting a third-party module built for leveraged positions on Aave v3, according to on-chain analysis by security firm SlowMist. Combined victim losses are estimated between $305,000 and $310,000.
The exploit targeted the FlashLoopAdapter, a module that users had enabled on their own wallets to automate leveraged strategies on Aave v3. Neither Aave v3 nor Safe's core infrastructure was compromised. The attacker forged Safe authentication to bypass the module's access controls and then steered its execution paths to move assets out of both multisigs.
SlowMist reported that the exploiter repaid approximately 1,300 WETH of Aave debt attached to the wallets, unlocking the collateral held behind it. That collateral was the target of the entire operation.
The attack ran in a single transaction. It began with a WETH flash loan sourced from Morpho. With the borrowed funds, the attacker paid down between roughly 1,300 and 1,335 WETH of Aave debt held by the two Safes. From one Safe, the attacker withdrew collateral worth around 1,306.48 WETH, with a smaller sum pulled from the second wallet. After repaying the flash loan, the attacker's net profit stood at approximately 114.09 ETH.
Root cause: unvalidated caller input
Post-incident analyses traced the flaw to the module's open() and close() functions, the routines that set up and unwind leveraged positions. The problem was weak validation of responses controlled by the caller. The module accepted answers from whoever invoked it without confirming they originated from a legitimate Safe contract.
SlowMist and fellow security firm ExVul both published alerts after the attack. The two affected Safes disabled the vulnerable module immediately to prevent further losses.
Why modules carry outsized risk
Safe wallets owe much of their adoption to modularity. Owners can attach extensions that automate strategies, manage permissions or connect to lending protocols such as Aave. But a module with broad execution rights over a wallet effectively inherits that wallet's power. A multisig's signature requirements offer little protection once a module has been granted a path around them.
For users running leveraged strategies through third-party tooling, the security of a position depends on the least-audited contract with permission to touch it. Holders of Safe multisigs would be well served to review which modules are enabled on their wallets. Any module that can move funds deserves at least as much scrutiny as the wallet's signer set, since it can act without collecting signatures.
For Aave, the protocol functioned exactly as designed: debt was repaid, so collateral was released. The failure sat entirely in the adapter that decided who was permitted to trigger those actions.
The incident carries a direct lesson for developers of leverage tools and wallet extensions: validating every caller-supplied input, especially anything claiming to originate from a trusted contract, is the baseline. Flash loans let attackers bring enormous temporary capital to bear on any flaw, meaning even narrow bugs can unlock large balances.
With both affected Safes now having disabled the module, attention shifts to whether other wallets still have the FlashLoopAdapter enabled — and to whether further incidents surface before a patched or deprecated version of the module circulates through the Safe ecosystem.
via Crypto Briefing (Source)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles