0x7b04a3a17b04…7b04a3a4

ConfirmedSecurity605 vB43 sat/vB3 min decode

Third-Party Aave Adapter Exploit Drains 114 ETH from Two Safe Wallets

An attacker spoofed a Safe module check in a third-party Aave v3 lending adapter to drain 114 ETH — over $300,000 — from two multisig wallets, blockchain security firm SlowMist reported on Oct. 2.

Crypto hackers exploit third-party Aave tool to steal 114 ETH
WitnessCrypto hackers exploit third-party Aave tool to steal 114 ETHAI-generated

Outputs

  1. 114.09 ETH (over $300,000) was stolen from two Safe multisig wallets via a third-party Aave v3 adapter, reported by SlowMist on Oct. 2.

  2. Roughly 1,300 WETH of debt was repaid by the attacker during the exploit to unlock the underlying collateral.

  3. Aave v3 core smart contracts were unaffected; Aave holds more than $33 billion in total value locked.

  4. The attacker deployed a fake Safe contract to bypass the FlashLoopAdapter's module authentication check, then invoked Safe's execTransactionFromModule.

  5. weETH and Aave-linked collateral were drained from the two affected multisig wallets.

A third-party lending adapter built on Aave v3 lost 114.09 ETH — roughly $300,000 — when an attacker spoofed a Safe module check and drained collateral from two multisig wallets, blockchain security firm SlowMist reported on Oct. 2.

The exploit hit the FlashLoopAdapter, a tool that operates on top of Aave v3 positions. SlowMist estimated the direct loss at 114.09 ETH. The attacker also repaid about 1,300 WETH of outstanding debt during the operation to unlock the underlying collateral.

Aave founder Stani Kulechov said the incident did not touch Aave's core smart contracts. "This is not Aave v3 contract, it's third party external adapter built on top of Aave, zero effect on Aave v3," he posted on X.

How did the attacker bypass the adapter?

SlowMist traced the vulnerability to the FlashLoopAdapter's open() and close() functions. Both routines checked whether a calling Safe had enabled the adapter as a module. The check could be spoofed.

The attacker deployed a fake Safe contract that returned a positive response whenever the adapter queried its module status. The adapter accepted the forged authentication and moved to its internal swap routine.

The more damaging weakness came next. The adapter accepted caller-supplied router addresses and calldata for an external contract call. The attacker pointed the router back at the victim Safe and supplied instructions invoking Safe's execTransactionFromModule function.

Because the FlashLoopAdapter was already registered as an enabled module on the affected wallets, the forged transaction gained legitimate execution rights inside the victims' Safes. From there, the attacker withdrew weETH and Aave-linked collateral.

What is the scope of the exposure?

The immediate losses sat with users who had enabled the FlashLoopAdapter on their Safe wallets. SlowMist has not publicly listed the wallet addresses or operators affected.

Key parameters from the incident:

  • Direct loss: 114.09 ETH
  • Debt repaid during attack: ~1,300 WETH
  • Wallets compromised: 2 Safe multisigs
  • Aave v3 core contracts: untouched

The flash-loan-style debt repayment — roughly 1,300 WETH — suggests the attacker had access to substantial borrowed liquidity at the moment of execution. Aave, the largest decentralized lending protocol by deposits, holds more than $33 billion in total value locked across its deployments. None of that capital is at risk from the adapter flaw, according to Kulechov's statement. Protocol-level audits and Aave's governance-controlled parameter changes were not implicated.

The exposure, however, is structural rather than contained. Any other Safe wallet that enabled the FlashLoopAdapter as a module may still carry the same authentication gap. SlowMist has not disclosed whether additional wallets face risk.

What does this say about DeFi integration risk?

The incident underscores a recurring pattern in decentralized finance: a base protocol can remain operationally intact while integrations layered on top of it introduce separate attack surfaces. Aave v3's lending markets, liquidation engine, and price oracles were untouched. The breach sat in middleware — a tool meant to extend Aave's functionality to multisig users.

For institutional counterparties and treasury operators, the episode sharpens the case for module allowlisting and per-integration audits. Safe modules execute with the same authority as a multisig signer, so a compromised module effectively compromises the wallet.

For Aave, the near-term question is whether the FlashLoopAdapter's developers will publish a full list of affected positions, a patched contract, and a migration path before the same authentication flaw is reused against other wallets. The open question is whether the adapter's maintainers will disable the vulnerable code path or whether Aave governance will eventually need to weigh restrictions on third-party module integrations running against v3 positions.

via x.com (Original)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles