$305K Loss: FlashLoopAdapter Exploit Hits Two Aave-Linked Safes
A recent security alert from Defimon Alerts on X has revealed an exploit of a custom Ethereum module used to manage leveraged Aave V3 positions through Safe wallets. The incident resulted in an estimated loss of about $305,000.
The affected component was the FlashLoopAdapter module, which is designed to open and close leveraged Aave positions for Safe wallets that have enabled it. However, an attacker-controlled contract was able to pass the module's access-control checks and use its execution path to move collateral from two affected Safes.
According to the alert, the reported weakness involved the custom FlashLoopAdapter contract built around Aave V3, rather than in Aave V3's core lending contracts. The attacker used a flash loan from Morpho to form part of the transaction sequence involving the FlashLoopAdapter and affected Safe wallets.