Ethereum Safe Wallets Drained of 114.09 ETH in Module Flaw Attack
A recent security breach has affected two Safe multisig wallets on the Ethereum blockchain, draining approximately 114.09 ETH.
The incident occurred due to a vulnerability in the FlashLoopAdapter contract, which is used for looped staking. This type of staking involves depositing a liquid staking token as collateral and borrowing ether against it. The borrowed ether is then swapped back into the same staking token and deposited again, creating a cycle that can raise earnings but also increases debt.
A helper contract bundles these steps into one transaction, and for such a contract to work with a multisig wallet, it must be registered as a module. However, this module can act without requiring the full signing quorum, allowing an attacker to bypass access control.
The attack was carried out by using a forged Safe contract that answered permission queries with 'yes', and exploiting the internal _swap() function's vulnerability in determining the router and call data. The attacker repaid 1,300 WETH of debt using a flash loan from Morpho, leaving them with a profit of approximately 114.09 ETH.
Aave v3's core pools and Safe core contracts were not affected by this incident, as the vulnerability lay in the FlashLoopAdapter contract outside both systems.