Aave v3 Exploit via FlashLoopAdapter Module Results in $310K Losses
A recent security exploit on Aave v3 resulted in losses of up to $310K after an attacker targeted Safe multisig wallets. The attack occurred on October 1, 2026, and was flagged by security firm SlowMist.
The exploiter used the FlashLoopAdapter module, a tool designed to help users build leveraged positions on Aave v3. However, the module had a weak validation of responses controlled by the caller, allowing the attacker to forge Safe authentication and repay Aave debt to unlock collateral.
According to SlowMist, the attacker deployed a fake contract that impersonated Safe authentication, which allowed them to move assets out of the two multisigs. The attack was carried out in a single transaction, with the attacker using a WETH flash loan sourced from Morpho to pay down Aave debt and free up collateral.
The incident highlights the importance of validating every caller-supplied input, especially when it comes to trusted contracts. Developers building leverage tools and wallet extensions must prioritize security measures to prevent similar attacks in the future.