Saturday, 3 October 2026
BTC $84,535 −2.01% ETH $2,675 −1.86% SOL $119.05 −2.91% XRP $1.49 −2.23% BNB $766.77 −1.53% DOGE $0.093 −3.22% ADA $0.246 −2.99% TON $1.49 −5.15% AVAX $10.85 −2.18% BTC $84,535 −2.01% ETH $2,675 −1.86% SOL $119.05 −2.91% XRP $1.49 −2.23% BNB $766.77 −1.53% DOGE $0.093 −3.22% ADA $0.246 −2.99% TON $1.49 −5.15% AVAX $10.85 −2.18%
GPreferred sourceon Google
Advertise
Latest
DeFi

Third-party Aave adapter exploit drains 114 ETH from Safes

Security analysts monitoring blockchain transaction data on dark operations center screens after a DeFi adapter exploit

An attacker drained about 114.09 ETH — worth roughly $305,000 — from two Safe multisig wallets on Oct. 2 by exploiting an access-control flaw in a third-party adapter built on Aave v3, according to Cryptoslate. Blockchain security firm SlowMist traced the loss to the FlashLoopAdapter, a module used to open and close leveraged Aave v3 positions through Safe wallets, while Aave’s own contracts were untouched.

Aave v3’s core smart contracts were not affected. SlowMist said the attacker compromised two Safe multisig wallets through a flaw in the third-party FlashLoopAdapter, bypassing its authentication check to drain about 114.09 ETH, or roughly $305,000. Aave founder Stani Kulechov confirmed the incident involved external infrastructure built on top of Aave, not the protocol itself.

Kulechov addressed the distinction directly, saying the affected code was not part of the protocol’s base layer. Cryptoslate reported him as saying the incident involved a third-party external adapter built on top of Aave rather than an Aave v3 contract, with no effect on the v3 codebase. For the largest decentralized lending protocol, which the report said holds more than $33 billion in total value locked, that separation is the central fact of the story.

The authentication bypass at the centre of the exploit

SlowMist attributed the vulnerability to the adapter’s open() and close() functions, which verified whether the calling Safe had enabled the adapter as a module. That check could be spoofed. The attacker created a fake Safe contract that always returned a positive response when asked whether the module was enabled, and the adapter accepted the forged authentication before proceeding to its internal swap function.

The more serious weakness followed. The adapter allowed the caller to specify both the router and the calldata used in an external contract call. According to SlowMist, the attacker pointed the router back at the victim Safe and supplied instructions invoking Safe’s execTransactionFromModule function. Because the FlashLoopAdapter was already enabled as a module on the affected wallets, that path let the attacker execute transactions through the victims’ Safes and withdraw the collateral.

Both outlets reported the same loss figure. Cointelegraph, which also covered the incident, said SlowMist’s estimate of about 114.09 ETH equated to roughly $305,000. The two reports are consistent on the amount, the number of wallets, and the adapter at fault. Cointelegraph additionally noted that SlowMist identified the vulnerable FlashLoopAdapter contract and the attacker’s wallet, and that the security firm did not report any losses to Aave v3 itself.

Why it matters

The incident is a reminder that in decentralized finance, a protocol can remain secure on its own terms while the integrations layered around it open separate attack surfaces. Users of the FlashLoopAdapter carry that exposure, not Aave’s base contracts. The pattern has become familiar: an audited core protocol, an unaudited or lightly reviewed peripheral module, and a configuration mistake that turns a convenience tool into an entry point. For borrowers who rely on third-party position managers, the loss was real regardless of where the code lived on the stack.

What to watch

The immediate question is how widely the vulnerable module was deployed — specifically, whether other wallets enabled the same adapter and whether its developers can identify additional affected positions before attackers reuse the authentication flaw. SlowMist’s disclosure named the vulnerable contract and the attacker’s wallet, which gives other integrators a starting point for checking their own exposure.

Frequently Asked Questions

Was Aave v3 itself hacked in this incident?

No. Aave founder Stani Kulechov stated that the exploit involved a third-party external adapter built on top of Aave, not Aave v3’s core smart contracts, and that the protocol itself had zero effect from the attack.

How much was stolen in the third-party Aave adapter exploit?

SlowMist estimated the direct loss at about 114.09 ETH, which both Cryptoslate and Cointelegraph valued at roughly $305,000. Roughly 1,300 WETH of debt was also repaid during the attack to unlock collateral tied to the positions.

How did the attacker bypass the wallet authorization check?

The attacker created a fake Safe contract that always returned a positive response when asked whether the module was enabled. The adapter accepted that forged authentication and then let the caller specify the router and calldata for an external contract call.

Which wallets and assets were affected?

Two Safe multisig wallets were compromised. SlowMist said the attacker used the technique to withdraw weETH and collateral associated with Aave positions from those wallets.

What should users of the FlashLoopAdapter do now?

Investigation is still underway. The open question is whether other wallets enabled the same module and whether the adapter’s developers will identify additional affected positions before attackers reuse the same authentication flaw.

Sources: CryptoSlate, Cointelegraph

Not investment adviceBitcoinWorld publishes news and analysis for information only. Nothing here is a recommendation to buy, sell or hold any asset. Digital assets are volatile and you can lose your entire capital. Consider your own circumstances and speak to a regulated adviser before acting. Read the full disclaimer.

Keshav Aggarwal

Co-Founder & Responsible Editor

Keshav Aggarwal is the Co-Founder & CEO of BitcoinWorld, a Google News - indexed publication covering crypto, AI, and forex markets since 2020. A blockchain investor and trader with over six years in the digital-asset space, he built one of India's most active crypto investor communities and has guided thousands of retail participants through their first investments in the asset class. At BitcoinWorld, he sets editorial direction across the newsroom and reports on the business of crypto, AI, and Web3 - tracking the funding rounds, product launches, and regulatory shifts shaping the future of finance and frontier technology.

Spotted an error in this article? We correct openly and log every change.Report a correction

More in DeFi

See all →