Aave-Linked Exploit Drains $305K From Two Safe Wallets
A recent exploit has drained $305,000 in ETH from two Safe wallets on Ethereum. The hacker used a third-party contract linked to Aave V3, bypassing a contract check and unlocking the wallets' collateral.
The attacker exploited a weakness in FlashLoopAdapter, a custom automation layer that manages leveraged positions on Aave V3. They bypassed the Safe authentication check in a single transaction and used a Morpho WETH flash loan to repay debt and unlock collateral held by the affected wallets.
The main weakness came from the adapter's access-control system, which checked whether the module was enabled through a Safe contract. However, the attacker used a fake Safe that returned a positive response, allowing them to bypass the check and control the router and transaction data used by the adapter.