A custom Safe module built to manage leveraged Aave positions was exploited on Ethereum on Oct. 1, and the real story is brutally simple: the attacker abused bad access control, not Aave v3 itself.
- Target: FlashLoopAdapter, a third-party Safe module for leveraged Aave v3 positions
- Chain: Ethereum
- Estimated loss: about $305, 000
- Attacker’s retained value: about 114.09-114.1 ETH
- Aave v3: not affected, according to Stani Kulechov
The exploit is a reminder that in DeFi, the base protocol is often not what gets you clipped. It is the custom plumbing bolted on top, the adapters, wrappers, modules, and “automation” layers that look useful right up until they turn into a backdoor.
According to Defimon Alerts, the attack was detected at 15:08:57 UTC on Oct. 1. Security firm SlowMist identified the attacker address as 0x42c2633438609881c8fBAb82414eb9A0c45F9353 and classified the incident as a smart contract vulnerability.
The vulnerable contract, FlashLoopAdapter, was listed at 0x16bb8b912da187870c23ec6756bb3fad061283d8. It was built to help manage leveraged positions through Safe wallets on Aave v3.
Safe wallets are smart contract wallets that can enable modules, permissioned contracts allowed to carry out certain actions on behalf of the wallet. That flexibility is useful. It also means a sloppy module can become a very expensive mistake.
In this case, the weak point was an authentication check inside the adapter’s open() and close() functions. The module checked whether ISafe(msg.sender).isModuleEnabled(address(this)) returned true. That works only if msg.sender is really a legitimate Safe.
The attacker sidestepped that assumption with a fake Safe contract that simply lied and returned true. In plain English: the adapter trusted the caller to be who it claimed to be, and the attacker built a convincing fake identity card.
Once that check was bypassed, the attacker used the adapter’s execution path to move through the victim Safes. Defimon and SlowMist said a Morpho flash loan was used to make the transaction sequence work.
A flash loan is temporary, uncollateralized borrowing that has to be repaid inside the same transaction. In legitimate DeFi, it is used for arbitrage or liquidations. In exploit land, it is often used to quickly repay debt, unlock collateral, and pull value out before the transaction finishes. Same tool, very different intent.
That is essentially what happened here. Roughly 1, 335 WETH of Aave debt was repaid for the first Safe, which unlocked about 1, 306 weETH from that wallet. A second Safe lost another 6.4 weETH.
The two affected wallets were:
- 0xcfedf95a3653a128dfc2e4288758a1a1850d169f
- 0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520
Defimon said both Safes shared the same single owner.
After the flash loan was repaid and the position was unwound, the attacker retained roughly 114.09 ETH to 114.1 ETH. That distinction matters. The reported $305, 000 figure is a gross loss estimate, not a clean profit number. In DeFi, money can move through a transaction, settle against debt, and leave the attacker with a much smaller net take than the headline number suggests.
Stani Kulechov, Aave’s founder, was direct about where the problem sat:
“This is not Aave v3 contract, it’s third party external adapter built on top of Aave, zero effect on Aave v3.”
That is the key line. The core Aave v3 contracts were not the broken part. The failure sat in a separate adapter layered on top of Aave, which is exactly the sort of integration risk that DeFi users tend to underestimate until it costs them real money.
For context, the Aave Protocol Documentation is the canonical place to track core protocol changes, but it does not magically secure every third-party widget people bolt onto it. That distinction is where a lot of users get lazy and then act shocked when the bill arrives.
SlowMist’s classification as a smart contract vulnerability is accurate, but the sharper description is simpler: this was an access-control failure. The adapter trusted the wrong caller, and that trust was enough to let an attacker steer a permissioned execution path inside the victim Safes.
Safe modules exist to make wallets smarter. They also make them more dangerous if the module is badly designed. Once enabled, a module can use functions like execTransactionFromModule to execute actions on behalf of the wallet. That is the whole point of the feature. It is also why a flawed module can become a privileged attack surface instead of a helpful tool.
For a deeper technical refresher, Safe Docs and the guide on Understanding and Implementing Safe Modules for Smart accounts explain how modules extend wallet behavior, and why that power demands paranoia, not blind trust.
The larger lesson is not “don’t use Safe” or “DeFi is busted.” That would be lazy nonsense. The real lesson is that composability cuts both ways. Every extra layer of automation adds another trust boundary, and every trust boundary is an opportunity for someone to screw up the logic and hand an attacker the keys.
There is also a pattern here. Prior Safe-related incidents involving other modules and adjacent setups, including FlashLoopAdapter Exploit Drains $305K from Aave-Linked Safe and Crypto Hacks Skyrocket to $1.7B in 2024 Due to Access, point in the same direction: the base wallet framework may be fine, but the custom module attached to it becomes the weak link. That is not a Safe-only problem. It is a crypto problem, full stop. The glue code is often where the bodies are buried.
What happened, step by step
The cleanest reconstruction looks like this:
- The attacker targeted FlashLoopAdapter’s caller checks.
- A fake Safe contract was used to satisfy the module’s authorization logic.
- The attacker used the adapter’s execution path through the victim Safes.
- A Morpho WETH flash loan supplied temporary liquidity.
- About 1, 335 WETH of debt was repaid for the first Safe.
- That unlocked about 1, 306 weETH from the first wallet.
- A second Safe lost 6.4 weETH.
- After settlement, the attacker retained about 114 ETH.
That sequence is why the exploit looks straightforward only after the fact. It was not a loud smash-and-grab. It was a carefully staged transaction that exploited one bad trust assumption inside a module that had been given permission to act.
That is the part people should pay attention to. The base protocol may be sound. The wallet may be sound. The module may be the piece that quietly turns the whole setup into a liability.
Key takeaways
- Was Aave v3 hacked?
No. The sources point to a third-party external adapter built on top of Aave, not Aave v3’s core lending contracts. - What was actually exploited?
An access-control flaw in FlashLoopAdapter let a fake Safe satisfy the module’s authorization check and abuse the execution path. - How much was lost?
About $305, 000 was reported as the loss estimate, but that is a gross figure, not the attacker’s net profit. - How much did the attacker keep?
Roughly 114.09-114.1 ETH remained after debt repayment and position unwinding. - Why use a flash loan?
The attacker needed temporary liquidity to repay debt, unlock collateral, and complete the exploit in one transaction. - Were multiple wallets affected?
Yes. Two Safe wallets were hit, and Defimon said both shared the same single owner. - What is the real lesson here?
Treat modules, adapters, and wrappers as privileged code. If they can move money, they need real authentication, real testing, and a healthy amount of paranoia.
The ugly truth is that most crypto losses do not come from the headline protocol people were watching. They come from the custom layer wrapped around it, where one weak check, one lazy assumption, or one fake identity is enough to turn automation into an exit ramp for an attacker.
For builders, that means tighter auth, better reviews, and less faith in clever plumbing. For users, it means not treating enabled modules like harmless add-ons. If a module can execute transactions on your behalf, it deserves the same suspicion you would give a stranger holding your keys. Because in practice, that is exactly what it is.
That suspicion should extend beyond a single exploit. Aave has been navigating tough calls across its markets, including plans to wind down low-adoption V3 markets and trim unused capital, while newer markets like Aave’s Monad Market Tops $100M in Two Days, but Incentives have shown how quickly incentives can distort activity. DeFi loves to market itself as clean code and elegant design; the reality is often messier, with incentives, wrappers, and governance all tugging in different directions.
And that is why the boring part matters. The best security wins are not glamorous. They are the unsexy ones: tighter permissions, fewer assumptions, and a lot less faith in some shiny adapter that promises to automate your way to freedom while quietly opening the door for a thief.
Further reading
A quick extra link for the folks keeping an eye on Aave’s housecleaning and the broader DeFi plumbing mess.